CVE-2025-15225: Sun.net Wmpro
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.
Affected products
- Sun.net Wmpro: from 5.0, up to and including 5.2
Published 2025-12-29. Last modified 2026-10-07.