Back to overview

CVE-2025-54945

CRITICAL
10.0
CVSS 4.0
Description
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.

Metadata

CVE ID
CVE-2025-54945
State
PUBLISHED
Assigner
ZUSO ART
Reserved
2025-08-01 07:35 UTC
Published
2025-08-30 03:50 UTC
Last updated
2026-01-30 03:36 UTC
Primary CWE
CWE-73
CWE-73: External Control of File Name or Path
Vendor / Product
SUNNET Technology Co., Ltd. / Corporate Training Management System
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SUNNET Technology Co., Ltd. Corporate Training Management System 0 < 10.11
Weakness (CWE)
CWESourceDescription
CWE-73 cna CWE-73: External Control of File Name or Path
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview