CVE-2025-54942

Severity CVSS v4.0:
CRITICAL
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/08/2025
Last modified:
30/01/2026

Description

A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun.net:ehrd_ctms:*:*:*:*:*:*:*:* 10.11 (excluding)


References to Advisories, Solutions, and Tools