CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Other sources
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SmarterTools SmarterMailto a version that resolves this vulnerability.Fixed in Build 9413 - Remove
Remove
SmarterTools SmarterMailfrom your environment.Discontinue use of the product or uninstall SmarterTools SmarterMail if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52691?
CVE-2025-52691 is a high-severity vulnerability that could allow unauthenticated attackers to upload arbitrary files to the mail server.
How do I fix CVE-2025-52691?
To mitigate CVE-2025-52691, update SmarterMail to a version above 100.0.9413 as soon as possible.
Who is affected by CVE-2025-52691?
CVE-2025-52691 affects all versions of SmarterMail up to and including 100.0.9413.
What types of attacks can be executed after exploiting CVE-2025-52691?
Exploitation of CVE-2025-52691 could potentially lead to remote code execution on the affected mail server.
Is it possible to exploit CVE-2025-52691 without authentication?
Yes, CVE-2025-52691 can be exploited by unauthenticated attackers, making it particularly dangerous.