Back to Database
Status published
Critical
CVE-2025-54945
SUNNET Corporate Training Management System - External Control of File Name or Path
Vulnerability Description
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54945
Credits & Attribution
No credits recorded in the NVD database.
References
More from SUNNET Technology Co., Ltd.
View All →CVE-2025-54946
SUNNET Corporate Training Management System - SQL Injection
Critical
9.3
CVE-2025-54944
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
Medium
6.9
CVE-2025-54943
SUNNET Corporate Training Management System - Missing Authorization
Critical
9.3
CVE-2025-54942
SUNNET Corporate Training Management System - Missing Authentication for Critical Function
Critical
9.3
CVE-2025-31340
Wisdom Master Pro - Improper Control of Filename for Include/Require Statement in PHP Program
Critical
9.9
Affected Vendor
SUNNET Technology Co., Ltd.
View all reports →Affected Software
Corporate Training Management System
Vulnerable Versions:
0
Timeline
Official Publish:
August 30th, 2025
Last Modified:
January 30th, 2026
Added to House:
July 22nd, 2026