CVE-2025-52691

9.5 CISA KEV

SmarterTools · SmarterMail

An unrestricted file upload vulnerability in SmarterTools SmarterMail allows unauthenticated attackers to achieve remote code execution on the mail server.

Executive summary

This critical vulnerability in SmarterTools SmarterMail is currently being exploited in the wild and allows unauthenticated attackers to execute arbitrary code on the server.

Vulnerability

The application fails to properly validate file types during upload, allowing an unauthenticated attacker to place malicious files in arbitrary locations on the server, which facilitates remote code execution.

Business impact

The exploitation of this vulnerability grants an attacker full control over the mail server, leading to a complete compromise of organizational communications, sensitive data exfiltration, and potential lateral movement into the internal network. With a CVSS score of 9.5, this flaw represents an extreme risk to business continuity and data integrity. The active exploitation of this vulnerability in the wild significantly elevates the urgency for immediate remediation.

Remediation

Immediate Action: Update SmarterMail to build 9413 or later immediately to patch the vulnerable file upload logic.

Proactive Monitoring: Review web server and application logs for suspicious file upload activity, particularly requests targeting directories outside the intended upload path or files with executable extensions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block file uploads containing suspicious headers or non-standard file extensions until the update is applied.

Exploitation status

Public Exploit Available: Yes, a Metasploit module exists and multiple public proof-of-concept repositories are available on GitHub.

Analyst recommendation

Given the confirmed active exploitation and the severity of the potential impact, organizations must prioritize patching SmarterMail to build 9413 without delay. Failure to address this vulnerability exposes the environment to immediate remote compromise. If patching is not immediately feasible, consider isolating the mail server from the public internet until the update is deployed.

More SmarterTools CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Published in the daily brief kev section
  24. Analyst report written
  25. Fix documented per CVE record

Sources

Originally found and disclosed by Chua Meng Han, per the CVE Program record.