Unrated severityNVD Advisory· Published Jul 21, 2025· Updated Jul 22, 2025
CVE-2025-52373
CVE-2025-52373
Description
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
Affected products
2- hMailServer/hMailServerdescription
- Range: 5.6.9-beta, 5.8.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.