CVE-2025-52488 is a high-severity vulnerability affecting DNN (DotNetNuke) versions 6.0.0 through 10.0.0, an open-source web content management platform. This flaw allows an unauthenticated attacker to remotely expose NTLM hashes to a third-party SMB server through a specially crafted series of interactions. The vulnerability carries a CVSS score of 8.6, indicating a high potential for impact with low attack complexity and no user interaction required. While there is no evidence of active exploitation, a Nuclei template exists for detection, and the vulnerability has garnered significant community discussion, suggesting potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 10.0.1CPE matchmatch criteria | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.