TROYANOSYVIRUS
Volver a CVEs

CVE-2025-52691

CRITICALCISA KEV
10.0

Descripcion

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Detalles CVE

Puntuacion CVSS v3.110.0
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado12/29/2025
Ultima modificacion1/27/2026
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorSmarterTools
ProductoSmarterMail
Nombre vulnerabilidadSmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
Fecha inclusion KEV2026-01-26
Fecha limite remediacion2026-02-16
Uso en ransomwareUnknown

Productos afectados

smartertools:smartermail

Debilidades (CWE)

CWE-434

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.