Critical severity10.0CISA KEVNVD Advisory· Published Dec 29, 2025· Updated Jun 17, 2026
CVE-2025-52691
CVE-2025-52691
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*range: <100.0.9413
- (no CPE)range: SmarterMail versions Build 9406 and earlier
Patches
Vulnerability mechanics
References
2- www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
3- Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli OrganizationsThe Hacker News · Jul 6, 2026
- Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)watchTowr Labs · Jan 22, 2026
- Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)watchTowr Labs · Jan 8, 2026