
CVE-2025-52691 Scanner - असुरक्षित SmarterMail इंस्टॉलेशन का पता लगाता है (CVSS 10.0 RCE)
SmarterMail में CVSS 10.0 RCE भेद्यता। क्या आपका मेल सर्वर असुरक्षित है?
CVE-2025-52691 के लिए तेज़, सटीक स्कैनर - एक गंभीर बिना प्रमाणीकरण वाली मनमाना फ़ाइल अपलोड भेद्यता जो SmarterMail सर्वरों पर रिमोट कोड निष्पादन सक्षम बनाती है।
CVE-2025-52691 SmarterMail में एक अधिकतम गंभीरता (CVSS 10.0) वाली भेद्यता है जो मनमाना फ़ाइल अपलोड के माध्यम से बिना प्रमाणीकरण के रिमोट कोड निष्पादन की अनुमति देती है।
मुख्य तथ्य:
Node.js स्कैनर:
Bash स्कैनर:
# Verify Node.js version
node --version # Should be v12.0.0 or higher
# Verify curl (for Bash scanner)
curl --version
# Clone and run
git clone https://github.com/nxgn-kd01/smartermail-cve-scanner.git
cd smartermail-cve-scanner
node scan.js https://mail.example.com
# Clone and run
git clone https://github.com/nxgn-kd01/smartermail-cve-scanner.git
cd smartermail-cve-scanner
chmod +x scan.sh
./scan.sh https://mail.example.com
# Node.js version
curl -O https://raw.githubusercontent.com/nxgn-kd01/smartermail-cve-scanner/main/scan.js
node scan.js https://mail.example.com
# Bash version
curl -O https://raw.githubusercontent.com/nxgn-kd01/smartermail-cve-scanner/main/scan.sh
chmod +x scan.sh
./scan.sh https://mail.example.com
# Using Node.js
node scan.js https://mail.example.com
# Using Bash
./scan.sh https://mail.example.com
node scan.js https://mail.example.com --verbose
./scan.sh https://mail.example.com -v
node scan.js https://mail.example.com --json
./scan.sh https://mail.example.com --json
node scan.js https://mail.example.com --ci
./scan.sh https://mail.example.com --ci
| कोड | अर्थ |
|---|---|
| 0 | असुरक्षित नहीं या स्कैन पूर्ण हुआ |
| 1 | असुरक्षित (--ci फ़्लैग उपयोग करने पर) |
| 2 | स्कैन त्रुटि हुई |
+============================================================+
| CVE-2025-52691 Scanner (SmarterMail RCE) |
+============================================================+
Severity: CRITICAL (CVSS 10.0)
Type: Unauthenticated Arbitrary File Upload -> RCE
[INFO] Scanning target: https://mail.example.com
Scan Results:
Target: https://mail.example.com
SmarterMail detected
Version: 100.0.9350
Build: 9350
STATUS: VULNERABLE
Build 9350 is affected by CVE-2025-52691
Remediation:
$ Upgrade to SmarterMail Build 9483 or later
$ Download: https://www.smartertools.com/smartermail/downloads
Scan Results:
Target: https://mail.example.com
SmarterMail detected
Version: 100.0.9483
Build: 9483
STATUS: NOT VULNERABLE
Build 9483 is patched
{
"vulnerability": "CVE-2025-52691",
"name": "SmarterMail RCE",
"severity": "CRITICAL",
"cvss": 10,
"target": "https://mail.example.com",
"smartermail_detected": true,
"version": "100.0.9350",
"build": 9350,
"status": "vulnerable",
"vulnerable": true,
"vulnerable_max_build": 9406,
"patched_min_build": 9413,
"recommended_build": 9483
}
name: SmarterMail Security Scan
on:
schedule:
- cron: '0 6 * * *' # Daily at 6 AM
workflow_dispatch:
jobs:
scan:
runs-on: ubuntu-latest
steps:
- name: Download Scanner
run: |
curl -O https://raw.githubusercontent.com/nxgn-kd01/smartermail-cve-scanner/main/scan.js
- name: Scan Mail Server
run: node scan.js ${{ secrets.MAIL_SERVER_URL }} --ci
security-scan:
stage: test
image: node:18
script:
- curl -O https://raw.githubusercontent.com/nxgn-kd01/smartermail-cve-scanner/main/scan.js
- node scan.js $MAIL_SERVER_URL --ci
allow_failure: false
स्कैनर:
node scan.js https://your-mail-server.com
नवीनतम संस्करण यहाँ से डाउनलोड करें: https://www.smartertools.com/smartermail/downloads
node scan.js https://your-mail-server.com --ci
यदि तत्काल अपग्रेड संभव नहीं है:
योगदान का स्वागत है! कृपया बेझिझक मुद्दे (issues) या पुल रिक्वेस्ट सबमिट करें।
MIT लाइसेंस - विवरण के लिए LICENSE फ़ाइल देखें
केवल अधिकृत उपयोग
यह टूल निम्नलिखित के लिए है:
किसी भी सिस्टम को स्कैन करने से पहले आपके पास स्पष्ट प्राधिकरण होना चाहिए।
कंप्यूटर सिस्टम की अनधिकृत स्कैनिंग निम्नलिखित कानूनों का उल्लंघन कर सकती है, जिनमें शामिल हैं लेकिन इन्हीं तक सीमित नहीं:
इस टूल के लेखक:
इस टूल का उपयोग करके, आप स्वीकार करते हैं कि आपके पास लक्षित सिस्टम को स्कैन करने का कानूनी अधिकार है और आप अपने कार्यों की पूरी ज़िम्मेदारी लेते हैं।
सुरक्षित रहें और अपने मेल सर्वरों को अपडेट रखें!
| विकल्प | विवरण |
|---|
-v, --verbose | विस्तृत आउटपुट दिखाएँ |
--json | परिणाम JSON के रूप में आउटपुट करें |
--ci | असुरक्षित होने पर कोड 1 के साथ बाहर निकलें (CI/CD के लिए) |
-t, --timeout | कनेक्शन टाइमआउट (डिफ़ॉल्ट: 10s/10000ms) |
-h, --help | सहायता संदेश दिखाएँ |
| गुण | मान |
|---|
| CVE ID | CVE-2025-52691 |
| CVSS स्कोर | 10.0 (CRITICAL) |
| CVSS वेक्टर | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| हमला वेक्टर | नेटवर्क |
| प्रमाणीकरण | कोई आवश्यक नहीं |
| प्रभाव | पूर्ण सिस्टम समझौता |