CVE-2025-15226
9.8Sunnet · WMPro
Sunnet WMPro versions 5.0 through 5.2 contain an unrestricted file upload vulnerability, allowing unauthenticated remote attackers to execute arbitrary code via uploaded web shell backdoors.
Executive summary
An unauthenticated remote code execution vulnerability in Sunnet WMPro poses a critical risk to server integrity and data confidentiality.
Vulnerability
The application suffers from an unrestricted file upload flaw (CWE-434), which permits unauthenticated attackers to upload malicious files. By successfully uploading a web shell, an attacker can achieve arbitrary code execution on the underlying server.
Business impact
Successful exploitation grants an attacker full control over the application server, leading to potential data exfiltration, system compromise, and significant operational disruption. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it requires no user interaction or authentication to weaponize.
Remediation
Immediate Action: Contact the vendor immediately to obtain and install the necessary security patches and verify current system settings.
Proactive Monitoring: Review web server access logs for requests targeting file upload endpoints that result in the creation of executable file types or suspicious script files.
Compensating Controls: Implement a Web Application Firewall (WAF) to block unauthorized file uploads and restrict access to administrative directories where such files might be executed.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention. Organizations utilizing Sunnet WMPro versions 5.0 through 5.2 must prioritize vendor communication to secure the environment against potential remote code execution. Failure to remediate this flaw exposes the organization to total system compromise.
More Sunnet CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Analyst report written
- Fix documented per CVE record