目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-52691— SmarterTools SmarterMail 安全漏洞

一分钟漏洞结论

影响对象
SmarterTools SmarterMail
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

SmarterTools SmarterMail是SmarterTools公司的一套邮件服务器软件。该软件支持垃圾邮件过滤、数据统计、简单邮件传输协议SMTP验证等功能。 SmarterTools SmarterMail存在安全漏洞,该漏洞源于未经验证的攻击者可上传任意文件,可能导致远程代码执行。

CVSS 10.0 · Critical KEV · 勒索软件 EPSS 85.66% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-52691 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Upload Arbitrary Files
来源: CVE Program / CVE List V5
Vulnerability Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
SmarterTools SmarterMail 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
SmarterTools SmarterMail是SmarterTools公司的一套邮件服务器软件。该软件支持垃圾邮件过滤、数据统计、简单邮件传输协议SMTP验证等功能。 SmarterTools SmarterMail存在安全漏洞,该漏洞源于未经验证的攻击者可上传任意文件,可能导致远程代码执行。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
SmarterTools SmarterMail SmarterMail versions Build 9406 and earlier -

二、漏洞 CVE-2025-52691 的公开POC

# POC 描述 源链接 神龙链接
1 Mail server contains an unrestricted file upload vulnerability allowing unauthenticated attackers to upload arbitrary files to any location, potentially enabling remote code execution. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-52691.yaml POC详情
2 None https://github.com/yt2w/CVE-2025-52691 POC详情
3 Detection for CVE-2025-52691 https://github.com/rxerium/CVE-2025-52691 POC详情
4 CVE-2025-52691 https://github.com/Ashwesker/Ashwesker-CVE-2025-52691 POC详情
5 This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detection only and does not exploit the vulnerability. https://github.com/you-ssef9/CVE-2025-52691 POC详情
6 An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691. https://github.com/DeathShotXD/CVE-2025-52691-APT-PoC POC详情
7 None https://github.com/sajjadsiam/CVE-2025-52691-poc POC详情
8 CVE‑2025‑52691 - SmarterMail Arbitrary File Upload Vulnerability https://github.com/hilwa24/CVE-2025-52691 POC详情
9 CVE-2025-52691 Scanner - Detects vulnerable SmarterMail installations (CVSS 10.0 RCE) https://github.com/nxgn-kd01/smartermail-cve-scanner POC详情
10 None https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691 POC详情
11 None https://github.com/rimbadirgantara/CVE-2025-52691-poc POC详情
12 CVE-2025-52691 https://github.com/mohammadzarnian1357/Ashwesker-CVE-2025-52691 POC详情
13 CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script. https://github.com/ninjazan420/CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-52691 的情报信息

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-52691

暂无评论


发表评论