CVE-2025-52691
CRITICAL KEV NUCLEISmartertools Smartermail < 100.0.9413 - Unrestricted File Upload
Title source: ruleDescription
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Exploits (12)
nomisec
SCANNER
17 stars
by watchtowrlabs · remote
https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691
nomisec
WORKING POC
4 stars
by DeathShotXD · poc
https://github.com/DeathShotXD/CVE-2025-52691-APT-PoC
nomisec
WORKING POC
1 stars
by ninjazan420 · remote
https://github.com/ninjazan420/CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001
nomisec
WORKING POC
1 stars
by rimbadirgantara · remote
https://github.com/rimbadirgantara/CVE-2025-52691-poc
nomisec
SCANNER
by mohammadzarnian1357 · poc
https://github.com/mohammadzarnian1357/Ashwesker-CVE-2025-52691
metasploit
WORKING POC
EXCELLENT
by Piotr Bazydlo, Sina Kheirkhah, jheysel-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/smartermail_guid_file_upload.rb
Nuclei Templates (1)
SmarterMail - Unrestricted File Upload
CRITICALVERIFIEDby DhiyaneshDK,watchTowr
Shodan:
html:"SmarterMail"
References (3)
Scores
CVSS v3
10.0
EPSS
0.7994
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2026-01-26
VulnCheck KEV
2026-01-22
ENISA EUVD
EUVD-2025-205544
Classification
CWE
CWE-434
Status
published
Affected Products (1)
smartertools/smartermail
< 100.0.9413
Timeline
Published
Dec 29, 2025
KEV Added
Jan 26, 2026
Tracked Since
Feb 18, 2026