CVE-2025-26705
Published: 11 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2025-26705 is an Improper Privilege Management vulnerability (CWE-269) in ZTE GoldenDB that allows privilege escalation. The issue affects GoldenDB versions from 6.1.03 through 6.1.03.05, as published on 2025-03-11.
The vulnerability has a CVSS v3.1 base score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating it is exploitable over the network with low attack complexity, requiring no privileges, no user interaction, and unchanged scope. Unauthenticated remote attackers can leverage this flaw to escalate privileges, resulting in low-impact disclosure of confidential information without affecting integrity or availability.
Mitigation guidance is available in the ZTE security bulletin at https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/577084989971263576.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The CVE describes an improper privilege management vulnerability that directly enables unauthenticated remote attackers to escalate privileges in the GoldenDB application.