CRITICAL
CVE-2025-52691
CVSS
10
KEV
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Summary dbcve.org
An unauthenticated attacker can upload arbitrary files to any location on the affected mail server. Combined with the ability to place files in any directory, this essentially provides remote code execution capability, as the attacker can overwrite system files, configuration files, or place executable scripts in web-accessible directories.
Mitigation
Apply vendor patches immediately when available; in the interim, restrict network exposure of the mail server to trusted networks only, and disable or severely restrict file attachment handling features if possible.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
85.66%
Probability of exploitation in next 30 days
99.7th percentile
References
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/
Third Party Advisory
https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.