← Back to CVE List
Vulnerability Intelligence Report
Upload Arbitrary Files

CVE-2025-52691

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:85.46%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-434 ↗CWE-434 Unrestricted Upload of File with Dangerous Type

Affected Products & Versions

Vendor Product Affected Versions
SmarterTools SmarterMail SmarterMail versions Build 9406 and earlier (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
85.457%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCyber Security Agency of Singapore · CERT · Singapore
Reserved2025-06-19T06:04:41
Published2025-12-29T02:15:58
Patch Date2025-12-29
Last Updated2026-02-26T16:07:23

LINK COPIED TO CLIPBOARD