cbcvebase.
CVE-2025-52691
published 2025-12-29

CVE-2025-52691: Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-02-16
Exploited in the wild
EPSS
85.66%
99.7th percentile
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Affected

2 ranges
VendorProductVersion rangeFixed in
smartertoolssmartermail< 100.0.9413100.0.9413
smartertoolssmartermail——

Detection & IOCsextracted from sources · hover to see the quote

pathC:\Program Files (x86)\SmarterTools\SmarterMail\Service\wwwroot\result.txt↗
url/api/v1/auth/force-reset-password↗
url/api/v1/auth/authenticate-user↗
url/api/v1/settings/sysadmin/event-hook↗
url/api/v1/settings/sysadmin/domain-put↗
url/api/v1/settings/sysadmin/domain-delete/google.abc.com/true↗
url/api/v1/settings/sysadmin/event-hook-delete↗
  • →Detect exploitation of CVE-2025-52691 (arbitrary file upload) by monitoring for unauthenticated POST requests that upload files to web-accessible paths on SmarterMail servers, particularly writes to the wwwroot directory. ↗
  • →Alert on the presence of result.txt under the SmarterMail wwwroot path, which is used to store reconnaissance command output dropped by attackers. ↗
  • →Monitor SmarterMail application logs for rapid sequential HTTP POST requests to the attack chain endpoints from a single source IP, indicative of mass automated exploitation. ↗
  • →Flag HTTP requests to SmarterMail APIs carrying the User-Agent string 'python-requests/2.32.4', which was observed as the tool used by attackers in the wild. ↗
  • →Check Point IPS signature 'SmarterMail Arbitrary File Upload (CVE-2025-52691)' can be used for network-level detection of exploitation attempts. ↗
  • →Investigate SmarterMail System Events for newly created or modified event-hooks, especially those configured to execute OS commands when a new domain is added, as this is the post-exploitation RCE mechanism observed in the wild. ↗
  • ·CVE-2025-52691 (arbitrary file upload / RCE) is a distinct vulnerability from CVE-2026-23760 (authentication bypass / account takeover). The IP addresses and User-Agent IOCs listed in the Huntress report were observed in the context of CVE-2026-23760 exploitation, but Huntress explicitly notes that mass exploitation of CVE-2025-52691 was also ongoing simultaneously. ↗
  • ·The fix for CVE-2025-52691 is SmarterMail Build 9511 or later. Versions prior to this build are confirmed vulnerable. ↗

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.