CVE-2026-9668: SQL injection vulnerability in ZTE SCP product
With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently lead to slow database queries and expanded query coverage. This vulnerability features a low exploitation threshold, wide scope of impact, requires no external privilege escalation, and is classified as a high-priority fix.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs legitimate user credentials. No external privilege escalation is required after authentication.
What can a successful attacker do?
The attacker can submit malicious SQL statements to bypass authentication logic and run arbitrary database queries directly. This can expand accessible query coverage and cause slow database queries.
Does exploitation require user interaction or difficult attack conditions?
No user interaction is required, and the attack complexity is low. The CVSS vector identifies adjacent-network access as the attack vector.