PT-2025-53686 · Smartertools · Smartermail
Chua Meng Han
·
Published
2025-12-29
·
Updated
2026-01-22
·
CVE-2025-52691
CVSS v3.1
10
10
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SmarterMail versions prior to Build 9413
SmarterMail versions 9406 and earlier
Description
A critical vulnerability exists in SmarterMail that allows unauthenticated attackers to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. This flaw, tracked as CVE-2025-52691, has a CVSS score of 10.0, indicating maximum severity. Exploitation of this vulnerability could lead to full server compromise, data theft, and ransomware attacks. Approximately 8,000 internet-exposed SmarterMail servers were reported as vulnerable as of January 12, 2026, and a public Proof-of-Concept (PoC) exploit is available. The
/api/upload endpoint is particularly vulnerable, with the guid parameter within contextData susceptible to path traversal attacks. The Singapore Cyber Security Agency (CSA) has issued an alert regarding this vulnerability.Recommendations
Upgrade SmarterMail to Build 9413 or later.
For SmarterMail versions 9406 and earlier, apply the security update immediately.
Review server logs for suspicious file uploads or unexpected files in web-accessible paths.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2025-52691
Affected Products
Smartermail
References · 100
- 🔥 https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com⭐ 1 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-52691 · Security Note
- https://twitter.com/StrongKeepCyber/status/2011649683823772139 · Twitter Post
- https://t.me/cveNotify/147009 · Telegram Post
- https://twitter.com/You_sse_f1/status/2006021663305994387 · Twitter Post
- https://twitter.com/PPHM_HackerNews/status/2005906057445441852 · Twitter Post
- https://twitter.com/AnonNews_irc/status/2006114519198621888 · Twitter Post
- https://twitter.com/transilienceai/status/2008418632922264035 · Twitter Post
- https://twitter.com/CrowdCyber_Com/status/2006098713907745030 · Twitter Post
- https://twitter.com/0dayPublishing/status/2005472768888901917 · Twitter Post
- https://twitter.com/stooee_/status/2009701805521772806 · Twitter Post
- https://twitter.com/stooee_/status/2009339417190707234 · Twitter Post
- https://twitter.com/ox0ffff/status/2006403305539281089 · Twitter Post
- https://twitter.com/shetkar_pranay/status/2006425734114586941 · Twitter Post
- https://t.me/defcon_news/133443 · Telegram Post