216.73.217.22

CVE-2025-52691

· Published 29/12/2025 04:15 · Modified 05/03/2026 16:50 · Author: The MITRE Corporation

Labels: CVE-2025-52691 2025-12-295f57b9bf-260d-4433-bf07-b6a79e9bb7d4CVE-2025-52691CWE-434

Essential information

Published
29/12/2025 04:15
Modified
05/03/2026 16:50
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / mail server cpe:2.3:a:*:mail_server:*:*:*:*:*:*:*:*

References