CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-54942

CVSS 9.3v4.0pub. 2025-08-30upd. 2026-01-30

A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication.

🤖 AI Analysis
How it works

The system does not require authentication before granting access to critical functions related to application deployment (CWE-306: Missing Authentication for Critical Function). A remote attacker, without possessing an account or any credentials, can directly invoke these functions over the network. The absence of an identity verification mechanism means that no password or access token serves as a protective barrier.

Impact

An attacker can gain unauthorized access to the system's deployment functions, which may lead to violations of confidentiality, integrity, and availability of data and the entire training management system.

Mitigation & patch

Update SUNNET Corporate Training Management System to version 10.11 or later. Details are available in the manufacturer's references and security advisory: https://zuso.ai/advisory/za-2025-10

Who is affected

SUNNET Corporate Training Management System (Sun.Net Ehrd Ctms) in versions prior to 10.11

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sun.net Ehrd Ctms

    APP
    Sun.Net
    < 10.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-54943CRITICAL9.3PL ✓same product

Brak autoryzacji w SUNNET CTMS umożliwia nieautoryzowane wdrożenie aplikacji

CVE-2025-54945CRITICAL10.0PL ✓same product

RCE poprzez external control of file path w SUNNET CTMS

CVE-2025-54946CRITICAL9.3PL ✓same product

SQL Injection w SUNNET Corporate Training Management System

CVE-2024-10440CRITICAL9.8PL ✓same product

SQL Injection w eHDR CTMS (Sunnet) umożliwia nieautoryzowany dostęp do bazy

CVE-2026-7489HIGH8.7same product

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject ...