CVE-2025-46575 Details
Description
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
An information disclosure vulnerability exists in ZTE GoldenDB database versions 6.1.03.09, 6.1.03.10, 7.2.01.01, and Lite7.2.01.01. Attackers can exploit this vulnerability by manipulating error messages to access sensitive system information.
Users can upgrade to ZTE GoldenDB versions 6.1.03.11, 7.2.01.01P1, or Lite7.2.01.01P1. For assistance, contact the ZTE Global Customer Support Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/4693390139849392205 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-209 | Generation of Error Message Containing Sensitive Information | [email protected] |
| CWE-209 | Generation of Error Message Containing Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zte zxcloud goldendb | 6.1.03.09 6.1.03.10 7.2.01.01 - |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2025 | Initial Analysis | [email protected] |
| Apr 27, 2025 | New CVE Received | [email protected] |