vulns.co
/
GKData.io MCP

Back to CVEs

CVE-2025-52691 - SmarterMail unauthenticated arbitrary file upload

An unauthenticated attacker can upload arbitrary files to locations on the mail server, potentially enabling remote code execution.

Tags: file-upload, unauthenticated, rce, smartermail, exploited

Product
SmarterTools SmarterMail Build 9406 and earlier
Severity
critical (CVSS 10)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published / added
2025-12-29
Signals
CISA KEV

References and evidence