Impact
The vulnerability allows an attacker with legitimate ZTE SCP user credentials to inject malicious SQL statements that bypass the authentication logic and execute arbitrary queries against the database. This can lead to slow queries, broaden query coverage, and potentially expose or modify sensitive data stored in the system.
Affected Systems
The affected product is ZTE SCP. The versions impacted are not specified in the available data, so any deployment of the ZTE SCP product should be examined for susceptibility.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity level, and the EPSS score is not available. The vehicle for exploitation requires only legitimate user credentials and no additional privileges, making the threat reachable for insiders or compromised accounts. Because the vulnerability can be leveraged to bypass authentication and run arbitrary queries, the impact is significant enough to warrant a high‑priority fix, although it has not been listed in the CISA KEV catalog.
OpenCVE Enrichment