CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-54943

CVSS 9.3v4.0pub. 2025-08-30upd. 2026-01-30

A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.

🤖 AI Analysis
How it works

The system does not implement required access control mechanisms (CWE-862) when handling requests related to application deployment. An attacker can remotely send a crafted request to the vulnerable endpoint without needing a valid session or permissions. Lack of identity and authorization verification allows them to perform deployment operations that should be reserved exclusively for authorized administrators.

Impact

An attacker can remotely deploy any application in the training management system, which may lead to complete takeover of the environment, breach of employee and training data confidentiality, and disruption of platform continuity.

Mitigation & patch

The system should be updated to version 10.11 or newer. Detailed information is available in the manufacturer's guide at https://zuso.ai/advisory/za-2025-11. Until the patch is deployed, it is recommended to restrict network access to the system only to trusted hosts through firewall rules.

Who is affected

SUNNET Corporate Training Management System (Sun.Net Ehrd Ctms) in versions before 10.11

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sun.net Ehrd Ctms

    APP
    Sun.Net
    < 10.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-54942CRITICAL9.3PL ✓same product

Brak uwierzytelnienia w SUNNET CTMS — dostęp do funkcji wdrożeniowych

CVE-2025-54945CRITICAL10.0PL ✓same product

RCE poprzez external control of file path w SUNNET CTMS

CVE-2025-54946CRITICAL9.3PL ✓same product

SQL Injection w SUNNET Corporate Training Management System

CVE-2024-10440CRITICAL9.8PL ✓same product

SQL Injection w eHDR CTMS (Sunnet) umożliwia nieautoryzowany dostęp do bazy

CVE-2026-7489HIGH8.7same product

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject ...