CVE-2025-52691
Upload Arbitrary Files
- Published
- Dec 29, 2025
- Updated
- Feb 26, 2026
- Assigning CNA
- CSA
- Evidence observed
- Jan 26, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Sources
8- CVE-2025-52691-APT-PoCExploit
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691.
- Ashwesker-CVE-2025-52691Detection
CVE-2025-52691
- CVE-2025-52691-pocExploit
Proof-of-concept exploit for CVE-2025-52691: unauthenticated arbitrary file upload leading to RCE in SmarterMail. Includes vulnerability scanner, ASPX webshell uploader, and interactive shell for authorized security testing.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.