External risk intelligence

Sunnet WMPro Arbitrary File Upload Leads to Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-15226

The vulnerability involves an arbitrary file upload in a web application. Such applications are commonly deployed as internet-facing services, and the ability for an unauthenticated remote attacker to interact with the file upload functionality indicates it is intended to be reachable via the network, making public or external exposure a common deployment pattern for this type of software.

Unrestricted File Upload

Sun Net Wmpro

5.0 to 5.2

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in WMPro software developed by Sunnet. The issue allows unauthenticated remote attackers to upload and execute malicious code, potentially leading to server compromise. The main concern is confirming relevance and exposure within our environment.

  • Unauthenticated remote code execution via file upload.
  • Critical severity with broad remote exploitation potential.
  • Assess relevant systems for potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach this vulnerability by interacting with the WMPro web application over the network. Since no authentication is required, an unauthenticated remote attacker can upload a web shell backdoor, leading to arbitrary code execution on the server.

  • Unauthenticated remote access required.
  • Upload a web shell backdoor.
  • Arbitrary code execution on server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in WMPro could allow an unauthenticated remote attacker to upload and execute web shell backdoors. This could lead to arbitrary code execution on the server when the product is exposed to the network.

  • Arbitrary code execution on the server.
  • Upload and execute web shell backdoors.
  • Unauthenticated remote attackers can exploit.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WMPro application, developed by Sunnet, presents a critical Arbitrary File Upload vulnerability that demands immediate attention from infrastructure and application owners. The first actionable step involves pinpointing all WMPro deployments, assessing their network exposure, confirming business criticality, and identifying the specific team accountable for remediation to establish a risk-based action plan.

  • Identify WMPro deployments and owners.
  • Verify external reachability and business impact.
  • Plan remediation or mitigation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Sunnet WMPro and how is it used?

Sunnet WMPro is a web-based software application designed for server-side management and data processing tasks. It acts as a platform for handling various administrative functions, which often involves processing files uploaded by users. Because it serves as a central hub for these operations, it is frequently configured to be accessible over a network to support remote workflows.

What does an arbitrary file upload vulnerability mean in CVE-2025-15226?

This vulnerability is classified as CWE-434, which refers to Unrestricted Upload of File with Dangerous Type. It means the application fails to sufficiently validate the files a user submits. An attacker can exploit this weakness to upload a script, commonly called a web shell, directly to the server. Once the file is stored, the server can be tricked into executing it, granting the attacker control over the system.

How does an attacker trigger this vulnerability?

The flaw is triggered when an attacker sends a specially crafted request to the file upload feature of the WMPro application. Crucially, the attacker does not need to provide credentials or log in to complete this action. If the application is configured to strictly limit uploads to non-executable file types, the trigger would be unsuccessful; however, the current defect allows these protections to be bypassed entirely.

Do I need to worry if my WMPro instance is not internet-facing?

Halo Surface Signal indicates that while this vulnerability is designed for network interaction, your risk level depends on where the software is positioned. If your WMPro instance is strictly internal and unreachable from the public internet, the pool of potential attackers is limited to those already inside your network. Regardless of location, the ability to exploit this without authentication makes it a high-priority item for any deployment.

What should I do first to address CVE-2025-15226?

Start by performing a complete inventory to locate all active Sunnet WMPro installations within your infrastructure. Once identified, document the network placement of these systems and determine which business units are responsible for them. Prioritize these findings to verify the current configuration, establish a clear owner for the software, and prepare for necessary security updates or configuration changes.

References