CVE-2026-9668 PUBLISHED

SQL injection vulnerability in ZTE SCP product

Assigner: zte
Reserved: 27.05.2026 Published: 26.08.2026 Updated: 26.08.2026

With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently lead to slow database queries and expanded query coverage. This vulnerability features a low exploitation threshold, wide scope of impact, requires no external privilege escalation, and is classified as a high-priority fix.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CVSS Score: 6.3

Product Status

Vendor ZTE
Product SCP
Versions Default: unaffected
  • Version ZENIC-ONE-R20-SCP-V16.25.20.071 is affected

Credits

  • PPC Security Team and Dimitrios Tsilis finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-66 SQL Injection