Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sun.Net

First CVE: Jul 11, 2019Active for: 7 yearsTotal CVEs: 21
43.1
VTI Score
High

Sun.Net maintains a small portfolio of enterprise resource planning and web-based management applications, with a vulnerability profile that is disproportionately weighted toward critical-severity outcomes. The exposure concentrates in products such as EHRD CTMS and WMPro and recurs consistently through application-layer input-handling weaknesses, including SQL injection, cross-site scripting, path traversal, OS command injection, and unrestricted file uploads—vulnerability classes that reflect common gaps in server-side input validation and sanitization. These weakness patterns are characteristic of legacy web application architectures and suggest systemic validation deficiencies across the vendor's codebase that warrant sustained attention from defenders deploying these systems. Organizations running Sun.Net applications should prioritize input filtering, least-privilege execution contexts, and network segmentation to contain the blast radius of these predictable flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sun.Net over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 11, 2019
7 years ago
Most Recent CVE
May 2, 2026
83 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-7489HIGH
CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
May 2, 20268.835NONO
CVE-2025-54942CRITICAL
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality
Aug 30, 20259.834NONO
CVE-2025-15226CRITICAL
WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary
Dec 29, 20259.832NONO
CVE-2025-54946CRITICAL
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.
Aug 30, 20259.832NONO
CVE-2025-54945CRITICAL
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via
Aug 30, 20259.832NONO
CVE-2025-54943CRITICAL
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the
Aug 30, 20259.831NONO
CVE-2019-11062CRITICAL
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
Jul 11, 20199.831NONO
CVE-2026-7490HIGH
CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbit
May 2, 20267.230NONO
CVE-2025-54944CRITICAL
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a sp
Aug 30, 20259.830NONO
CVE-2024-10440CRITICAL
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents
Oct 28, 20249.826NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
24%
38%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (85.7%)
Unknown0 (0.0%)
Required3 (14.3%)
Privileges Required
Low3 (14.3%)
High3 (14.3%)
None15 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sun.Net.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sun.Net — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sun.Net's Products

View all 1 CNAs →

Top CWEs