Arbitrary File Read Vulnerability in WMPro by Sunnet
CVE-2025-15225

8.7HIGH

Key Information:

Vendor

Sunnet

Status
Vendor
CVE Published:
29 December 2025

What is CVE-2025-15225?

The WMPro application developed by Sunnet contains an Arbitrary File Read vulnerability that enables unauthenticated remote attackers to exploit Relative Path Traversal techniques. This can potentially allow them to access and read arbitrary files on the server, leading to exposure of sensitive information and further attacks. Proper security measures should be taken to mitigate this vulnerability and protect data integrity.

Affected Version(s)

WMPro 5.0 <= 5.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.