← Back

CVE-2025-52374

nvd nist
Published: Jul 21, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

Affected (2)

1 product
Hmailserver
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Hmailserver
Version 5.6.9 beta
Version 5.8.6

References (3)

Source: cve@mitre.org
Product
Source: cve@mitre.org
ExploitThird Party Advisory

Timeline

No history available yet.