CVE-2025-52691
CRITICAL10.0Remote code execCISA KEVRansomwarePublic PoCHigh EPSS
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- SmarterTools / SmarterMailSmarterMail versions Build 9406 and earlier – SmarterMail versions Build 9406 and earlier
Exploits & proofs of concept
- nucleiSmarterMail - Unrestricted File Uploadby DhiyaneshDK,watchTowr