Fiche vulnérabilité
CVE-2025-52691 : faille exploitée smartertools smartermail (CVSS 10.0)
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
En bref
- Sévérité
- Critique (CVSS 10.0)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 29 déc. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- smartertools smartermail
Correctif et mesures
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.