Unrated severityNVD Advisory· Published Aug 30, 2025· Updated Jan 30, 2026
SUNNET Corporate Training Management System - External Control of File Name or Path
CVE-2025-54945
Description
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
Affected products
2- Range: <10.11
- SUNNET Technology Co., Ltd./Corporate Training Management Systemv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- zuso.ai/advisory/za-2025-13mitrethird-party-advisory
News mentions
0No linked articles in our index yet.