---
cve: "CVE-2025-46579"
severity: "HIGH"
cvss: 8.4
epss: "30%"
vendor: "ZTE"
kev: false
exploited: false
published: "2025-04-27 02:15:16"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T07:34:36+02:00"
---

# CVE-2025-46579

> 8.4 HIGH

## Beschreibung

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/1036467615091601474>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-46579) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
