sun.net CVE Vulnerabilities & Metrics

Focus on sun.net vulnerabilities and metrics.

Last updated: 25 Nov 2025, 23:25 UTC

About sun.net Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sun.net. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sun.net CVEs: 16
Earliest CVE date: 11 Jul 2019, 19:15 UTC
Latest CVE date: 01 Sep 2025, 04:15 UTC

Latest CVE reference: CVE-2025-9570

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 9

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 200.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 200.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sun.net CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.62

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 15
4.0-6.9 0
7.0-8.9 0
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS sun.net CVEs

These are the five CVEs with the highest CVSS scores for sun.net, sorted by severity first and recency.

All CVEs for sun.net

CVE-2025-9570 sun.net vulnerability CVSS: 0 01 Sep 2025, 04:15 UTC

The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.

CVE-2025-9569 sun.net vulnerability CVSS: 0 01 Sep 2025, 03:15 UTC

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

CVE-2025-9568 sun.net vulnerability CVSS: 0 01 Sep 2025, 03:15 UTC

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

CVE-2025-9567 sun.net vulnerability CVSS: 0 01 Sep 2025, 03:15 UTC

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

CVE-2025-54946 sun.net vulnerability CVSS: 0 30 Aug 2025, 04:15 UTC

A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.

CVE-2025-54945 sun.net vulnerability CVSS: 0 30 Aug 2025, 04:15 UTC

An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.

CVE-2025-54944 sun.net vulnerability CVSS: 0 30 Aug 2025, 04:15 UTC

An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.

CVE-2025-54943 sun.net vulnerability CVSS: 0 30 Aug 2025, 04:15 UTC

A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.

CVE-2025-54942 sun.net vulnerability CVSS: 0 30 Aug 2025, 04:15 UTC

A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication.

CVE-2024-10440 sun.net vulnerability CVSS: 0 28 Oct 2024, 03:15 UTC

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.

CVE-2024-10439 sun.net vulnerability CVSS: 0 28 Oct 2024, 03:15 UTC

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

CVE-2024-10438 sun.net vulnerability CVSS: 0 28 Oct 2024, 03:15 UTC

The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.

CVE-2023-35851 sun.net vulnerability CVSS: 0 18 Sep 2023, 03:15 UTC

SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.

CVE-2023-35850 sun.net vulnerability CVSS: 0 18 Sep 2023, 03:15 UTC

SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege or a privileged account can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operations or disrupt service.

CVE-2023-24836 sun.net vulnerability CVSS: 0 27 Apr 2023, 02:15 UTC

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.

CVE-2019-11062 sun.net vulnerability CVSS: 10.0 11 Jul 2019, 19:15 UTC

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.