Vulnerability Description
CVE-2025-52691 is a critical unauthenticated arbitrary file upload vulnerability in SmarterTools’ SmarterMail software. The flaw allows unauthenticated attackers to upload arbitrary files to any location on the mail server, which can lead to remote code execution (RCE) and potentially result in full system compromise. The vulnerability has been assigned a CVSS v3.1 base score of 10.0.

See the full breakdown by country in Censys Platform →
| Field | Description |
| CVE-ID | CVE-2025-52691 — CVSS v3.1 base score of 10.0 — assigned by CSA |
| Vulnerability Description | A critical vulnerability in SmarterTools’ SmarterMail software allows unauthenticated attackers to upload arbitrary files to any location on the mail server, which can lead to remote code execution (RCE) and potentially result in full system compromise. |
| Date of Disclosure | December 28, 2025 |
| Affected Assets | SmarterMail (SmarterTools) |
| Vulnerable Software Versions | Build 9406 and earlier |
| PoC Available? | As of writing, no public proof-of-concept exploit has been released. |
| Exploitation Status | No known exploitation at time of writing. |
| Patch Status | Patch is available. SmarterTools has released SmarterMail Build 9413 to address this |
Censys Perspective
As of time of writing, Censys observes 16,109 exposed and potentially vulnerable hosts, trackable with the following Censys queries:
(host.services.endpoints.http.body: {"ng-app="smartermail"", "SmarterMail Copyright"} or host.services.endpoints.http.html_title="rntSmarterMailrn" or host.services.endpoints.http.favicons.hash_md5="1af343c2b059ae3da7b4a144d05db588")
or
(web.endpoints.http.body: {"ng-app="smartermail"", "SmarterMail Copyright"} or web.endpoints.http.html_title="rntSmarterMailrn" or web.endpoints.http.favicons.hash_md5="1af343c2b059ae3da7b4a144d05db588")
risks.name="Vulnerable SmarterMail [CVE-2025-52691]"
services.http.response.body: {"SmarterMail Copyright","ng-app="smartermail""} or services.http.response.html_title="rntSmarterMailrn" or services.http.response.favicons.md5_hash="1af343c2b059ae3da7b4a144d05db588"
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-52691
- https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/
- https://ccb.belgium.be/advisories/warning-critical-unauthenticated-arbitrary-file-upload-vulnerability-smartermail-server
- https://github.com/rxerium/CVE-2025-52691
- https://x.com/rxerium/status/2005898519723311544
- https://www.smartertools.com/smartermail/release-notes/current

