CVE-2025-52691

CRITICAL KEV NUCLEI

Smartertools Smartermail < 100.0.9413 - Unrestricted File Upload

Title source: rule

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Exploits (12)

nomisec SCANNER 18 stars
by rxerium · poc
https://github.com/rxerium/CVE-2025-52691
nomisec SCANNER 17 stars
by watchtowrlabs · remote
https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691
nomisec WORKING POC 4 stars
by DeathShotXD · poc
https://github.com/DeathShotXD/CVE-2025-52691-APT-PoC
nomisec WORKING POC 3 stars
by yt2w · remote
https://github.com/yt2w/CVE-2025-52691
nomisec SCANNER 1 stars
by nxgn-kd01 · poc
https://github.com/nxgn-kd01/smartermail-cve-scanner
nomisec WORKING POC 1 stars
by ninjazan420 · remote
https://github.com/ninjazan420/CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001
nomisec SCANNER 1 stars
by you-ssef9 · poc
https://github.com/you-ssef9/CVE-2025-52691
nomisec WORKING POC 1 stars
by rimbadirgantara · remote
https://github.com/rimbadirgantara/CVE-2025-52691-poc
nomisec SCANNER
by mohammadzarnian1357 · poc
https://github.com/mohammadzarnian1357/Ashwesker-CVE-2025-52691
nomisec WORKING POC
by hilwa24 · remote
https://github.com/hilwa24/CVE-2025-52691
metasploit WORKING POC EXCELLENT
by Piotr Bazydlo, Sina Kheirkhah, jheysel-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/smartermail_guid_file_upload.rb

Nuclei Templates (1)

SmarterMail - Unrestricted File Upload
CRITICALVERIFIEDby DhiyaneshDK,watchTowr
Shodan: html:"SmarterMail"

Scores

CVSS v3 10.0
EPSS 0.7994
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2026-01-26
VulnCheck KEV 2026-01-22
ENISA EUVD EUVD-2025-205544

Classification

CWE
CWE-434
Status published

Affected Products (1)

smartertools/smartermail < 100.0.9413

Timeline

Published Dec 29, 2025
KEV Added Jan 26, 2026
Tracked Since Feb 18, 2026