---
id: CVE-2025-52691
title: >-
  Successful exploitation of the vulnerability could allow an unauthenticated
  attacker to upload arbitrary files to any location on the mail server,
  potentially enabling remote code execution.
summary: >-
  Successful exploitation of the vulnerability could allow an unauthenticated
  attacker to upload arbitrary files to any location on the mail server,
  potentially enabling remote code execution.
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: smartertools
product: smartermail
affected:
  - smartermail < 100.0.9413
patched:
  - smartermail 100.0.9413
published: '2025-12-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T12:10:00.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52691'
references:
  - url: 'https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/'
    label: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
  - url: >-
      https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.85655
epssPercentile: 0.9972
kev: true
kevDateAdded: '2026-01-26'
kevDueDate: '2026-02-16'
kevRansomware: true
exploited: true
exploits:
  github: 9
  githubRepos:
    - 'https://github.com/rxerium/CVE-2025-52691'
    - 'https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691'
    - 'https://github.com/DeathShotXD/CVE-2025-52691-APT-PoC'
  metasploit:
    - exploit/multi/http/smartermail_guid_file_upload
  nuclei:
    - CVE-2025-52691
  checkedAt: '2026-10-07T12:29:35.595Z'
exploitAvailable: true
ingestedAt: '2026-10-07T12:29:01.325Z'
---

## Overview

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

## Affected

- `smartermail < 100.0.9413`

## Remediation

Upgrade past the affected range:

- `smartermail 100.0.9413`
