CVE-2025-52691
CRITICAL KEV NUCLEISmarterMail < 100.0.9413 - Unauthenticated Arbitrary File Upload and Remote Code Execution
Title source: llmExploitation Summary
CVE-2025-52691 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 26, 2026.
EIP tracks 11 public exploits from researchers including rxerium, watchtowrlabs, DeathShotXD, including a Metasploit module exploits/multi/http/smartermail_guid_file_upload.
A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a Nuclei template for detecting CVE-2025-52691, an arbitrary file upload vulnerability in SmarterMail. The template checks for vulnerable versions by extracting the build number from the login page and comparing it against the patched version.
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Exploits (11)
This repository contains a Nuclei template for detecting CVE-2025-52691, an arbitrary file upload vulnerability in SmarterMail. The template checks for vulnerable versions by extracting the build number from the login page and comparing it against the patched version.
This repository contains a Python script that detects CVE-2025-52691, a path traversal vulnerability in SmarterMail leading to unauthenticated RCE. The script attempts to upload a file to a specific directory to verify exploitability but does not execute arbitrary code.
This repository contains a functional exploit for CVE-2025-52691, a critical arbitrary file upload vulnerability in SmarterTools SmarterMail, leading to unauthenticated remote code execution (RCE). The PoC includes stealth features like randomized user agents, obfuscated ASPX web shells, and APT-level capabilities such as persistence and file exfiltration.
This repository contains a functional exploit for CVE-2025-52691, an unauthenticated arbitrary file upload vulnerability in SmarterMail (Build 9406 and earlier). The exploit uploads an ASPX webshell via multiple endpoints and methods, leveraging path traversal to achieve remote code execution.
This repository contains a functional exploit for CVE-2025-52691, which combines an authentication bypass (WT-2026-0001) and a pre-auth RCE via file upload in SmarterMail. The exploit automates a 3-phase attack to achieve SYSTEM-level command execution.
This repository contains a scanner for CVE-2025-52691, a critical unauthenticated arbitrary file upload vulnerability in SmarterMail. The scanner detects vulnerable versions by probing endpoints and comparing build numbers but does not exploit the vulnerability.
This repository contains a functional exploit for CVE-2025-52691, an unauthenticated arbitrary file upload vulnerability in SmarterMail leading to RCE. It includes a scanner (check.py), an exploit tool (pwn.py), and a reusable Python library (exploit.py) for uploading ASPX webshells via path traversal.
This repository contains a Python script that detects vulnerable SmarterMail versions affected by CVE-2025-52691 by checking the build number. It does not exploit the vulnerability but identifies potential targets.
The repository contains a functional Python exploit for CVE-2025-52691, an unauthenticated arbitrary file upload vulnerability in SmarterMail (build 9406 and earlier). The exploit automates uploading an ASPX webshell to the target server via multiple endpoints and methods, then verifies and executes commands.
The repository contains a Nuclei template for detecting SmarterMail versions vulnerable to CVE-2025-52691, an unauthenticated arbitrary file upload vulnerability. It checks for the presence of SmarterMail and compares the build version to determine vulnerability status.
This Metasploit module exploits a pre-authentication remote code execution vulnerability in SmarterTools SmarterMail by leveraging a directory traversal flaw in the `/api/upload` endpoint to upload a malicious ASPX web shell.
Nuclei Templates (1)
html:"SmarterMail"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H