References https://cloud.tencent.com/developer/article/2612397 https://www.ihonker.com/thread-34104-1-1.html https://www.sentinelone.com/vulnerability-database/cve-2025-52691/ https://fortiguard.fortinet.com/tw/outbreak-alert/smartertools-smartermail-rce https://horizon3.ai/attack-research/vulnerabilities/cve-2025-52691/ https://beazley.security/alerts-advisories/critical-vulnerability-in-smartermail-cve-2025-52691 https://censys.com/advisory/cve-2025-52691/ https://nvd.nist.gov/vuln/detail/CVE-2025-52691 https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/ https://rodelllemit.medium.com/replicating-cve-2025-52691-an-rce-via-unauthenticated-arbitrary-file-upload-critical-vulnerability-e6c796270192
Related VulnerabilitiesPoCCVE-2026-24423: SmarterMail - Remote Code ExecutionPoCSmarterMail ConnectToHub /api/v1/settings/sysadmin/connect-to-hub 命令执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 远程代码执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 权限管理不当漏洞PoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password ResetPoCSmarterMail /api/v1/auth/force-reset-password 权限绕过漏洞SmarterMail 存在任意文件上传漏洞SmarterMail 存在任意密码重置漏洞PoCCVE-2025-52691: SmarterMail - Unrestricted File UploadPoCCVE-2022-24384: SmarterTools SmarterTrack - Cross-Site Scripting