The Cybersecurity Agency of Singapore (CSA) has issued a high-priority alert concerning a serious cybersecurity flaw in the SmarterTools SmarterMail Email application. Known as CVE-2025-52691, this vulnerability has a CVSS score of 10.0 and offers unauthenticated remote code execution due to unrestricted file uploads.
The vulnerability identified by CSA allows anyone with access to the mail server to upload files to any directory. If an unauthorized party has access to locations on the mail server to execute malicious files (such as a PHP script or executable), the unauthorized user will have the same level of access as SmarterMail itself.
Scope & Impact
As a well-known email solution used by many small businesses, SmarterMail provides a variety of features, such as a secure email client, shared calendars, instant messaging, as well as other collaboration tools. SmarterMail is widely supported by many web hosting service providers (including ASPnix Web Hosting, Hostek, and simplehosting.ch).
Versions Affected: SmarterMail version 9406 and below
Fixed Version: SmarterMail version 9413 (available from October 9, 2025)
Recommended Version: SmarterMail version 9483 (available from December 18, 2025)
Vulnerability Description
Although the vulnerability does not appear to be currently exploited, the possibility of such attacks is of concern given that they are conducted without the need for authentication. A potential attacker could:
1. Upload malicious binaries or web shells;
2. Execute files with the full permissions of the SmarterMail service;
3. Have unauthorized access to the data on a mail server and utilize that mail server to engage in further attacks.
The report of this vulnerability came from Chua Meng Han from Centre for Strategic Infocomm Technologies (CSIT).
Vulnerability Mitigation
All individuals using SmarterMail are encouraged to:
1. Upgrade immediately to Build 9483 (and above).
2. Regularly check their server directories for unauthorized uploads.
3. Restrict permissions on the web-accessible directories used to host SmarterMail.
It is imperative that prompt updates be implemented to reduce the risk of the vulnerability being exploited remotely.
Source: The Hacker News