CVE-2025-52691

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

History

27 Jan 2026, 15:28

Type Values Removed Values Added
References () https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com - () https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com - Exploit, Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691 - US Government Resource

26 Jan 2026, 21:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691 -

22 Jan 2026, 18:16

Type Values Removed Values Added
References
  • {'url': 'https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

22 Jan 2026, 17:15

Type Values Removed Values Added
References
  • () https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/ -

08 Jan 2026, 19:15

Type Values Removed Values Added
References
  • () https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com -

02 Jan 2026, 15:05

Type Values Removed Values Added
CPE cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*
First Time Smartertools
Smartertools smartermail
References () https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/ - () https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/ - Third Party Advisory

29 Dec 2025, 17:15

Type Values Removed Values Added
CWE CWE-434

29 Dec 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-29 03:15

Updated : 2026-01-27 15:28


NVD link : CVE-2025-52691

Mitre link : CVE-2025-52691

CVE.ORG link : CVE-2025-52691


JSON object : View

Products Affected

smartertools

  • smartermail
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type