Medium severity4.6NVD Advisory· Published Jul 21, 2025· Updated Jun 17, 2026
CVE-2025-52373
CVE-2025-52373
Description
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:hmailserver:hmailserver:5.6.9:beta:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:hmailserver:hmailserver:5.6.9:beta:*:*:*:*:*:*
- cpe:2.3:a:hmailserver:hmailserver:5.8.6:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 5.8.6, 5.6.9-beta
Patches
Vulnerability mechanics
References
1- github.com/mojibake-dev/mojibake-CVE/blob/main/hMailServer/CVE-2025-52373.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.