Vulnerability Description
Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hmailserver | Hmailserver | 5.6.9 |
Related Weaknesses (CWE)
References
- https://github.com/hmailserver/hmailserverProduct
- https://github.com/mojibake-dev/hMailEnumExploitThird Party Advisory
- https://github.com/mojibake-dev/mojibake-CVE/blob/main/hMailServer/CVE-2025-5237ExploitThird Party Advisory
FAQ
What is CVE-2025-52374?
CVE-2025-52374 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServe...
How severe is CVE-2025-52374?
CVE-2025-52374 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52374?
Check the references section above for vendor advisories and patch information. Affected products include: Hmailserver Hmailserver.