
Generador de artefactos de detección para CVE-2025-52691, una path traversal previa a la autenticación que conduce a RCE no autenticado en SmarterMail. Sondea versiones vulnerables escribiendo un archivo ASPX en el directorio App_Data para confirmar la explotabilidad sin compromiso completo.
SmarterMail Pre-Auth RCE 1day Detection Artifact Generator Tool
El Generador de Artefactos de Detección intenta escribir el archivo .aspx en el directorio C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data (builds 94xx) o en el directorio C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data (build 16). Esto no conduce a una ejecución remota de código, solo prueba la explotabilidad.
El script fue probado en:
Algunas builds más antiguas (como SmarterMail 15) no fueron probadas.
Ejemplo de ejecución contra una instancia vulnerable:
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SmarterMail-CVE-2025-52691.py
(*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE
- Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
[+] VULNERABLE - file epoyn5_0.aspx got uploaded
Ejemplo de ejecución contra una instancia parcheada:
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SmarterMail-CVE-2025-52691.py
(*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE
- Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
[-] NOT VULNERABLE - patch applied (INVALID_GUID error message appeared)
Este script intenta detectar si SmarterMail es vulnerable a CVE-2025-52691 Pre-Auth RCE.
< SmarterMail 9413
<= SmarterMail 16.3.6989.16341
Para conocer las últimas investigaciones de seguridad, sigue al equipo de watchTowr Labs