CVE-2025-52488 affects DNN Platform versions 6.0.0 through 10.0.0. A pre-authentication upload-related handler validates an attacker-supplied filename before converting Unicode characters to legacy encodings. Fullwidth Unicode characters can be converted after validation into period and backslash characters, allowing construction of a rooted UNC path that bypasses the filename controls. When the application combines the storage directory with this now-rooted path and checks whether the file exists, .NET resolves the UNC path rather than retaining the intended storage directory, causing the DNN host to access an attacker-controlled SMB server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-52488, targeting DNN Platform (formerly DotNetNuke) versions 6.0.0 through before 10.0.1. The repo contains 6 files total, with main.py as the clear entry point, README.md for usage/documentation, and standard Python dependency/project files (.python-version, pyproject.toml, requirements.txt, uv.lock). The exploit is not part of a major offensive framework. main.py implements a lightweight exploit framework structure with helper classes such as Logger, Utils, BaseExploit, and DNNExploit. It uses requests for HTTP interaction, disables TLS verification warnings, supports concurrent execution across multiple targets, and accepts a target list plus an attacker-controlled SMB server as command-line arguments. Core capability: the code crafts a Unicode-normalized UNC-style path using fullwidth backslashes and a fullwidth period, then submits that payload to the DNNConnect CKE file upload handler at /Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/FileUploader.ashx. The intended effect is to abuse Windows/.NET path normalization so the target server attempts outbound SMB access to the supplied attacker host, disclosing NTLM authentication material. This is an NTLM hash disclosure/capture exploit, not an RCE payload. The exploit also appears to perform target validation/fingerprinting before exploitation by checking for DNN-related indicators such as dnn_IsMobile, dotnetnuke, dnnconnect, DNN Platform, and DotNetNuke. Based on the README and visible code structure, successful exploitation results in an HTTP request being sent to the vulnerable upload endpoint and an instruction to the operator to inspect SMB listener logs for inbound NTLM authentication attempts. Overall, this is an operational but basic exploit tool: it automates multi-target delivery of a hardcoded Unicode path payload to a known DNN endpoint in order to trigger outbound SMB authentication and capture NTLM hashes.
This repository contains a Python exploit for CVE-2025-52488, a high-severity NTLM hash disclosure vulnerability in DNN (DotNetNuke) versions 6.0.0 to before 10.0.1 running on Windows/IIS. The exploit leverages Unicode path normalization quirks in Windows/.NET to trick the DNN file upload endpoint into making SMB requests to an attacker-controlled server, thereby leaking NTLM authentication hashes. The main exploit logic is implemented in 'main.py', which supports multi-threaded execution against multiple targets listed in a file. The attacker must provide the address of their SMB server (such as Responder or Burp Collaborator) to capture the hashes. The exploit checks for DNN-specific indicators (such as the 'dnn_IsMobile' cookie and certain response strings) to confirm the target is running DNN. The repository includes standard Python project files and dependencies, with 'main.py' as the entry point. No hardcoded IPs or domains are present; the attacker supplies the SMB server address at runtime. The exploit is operational and can be used for real-world testing of vulnerable DNN instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pre-authentication DNN file-upload flaw in which Unicode-to-ASCII normalization bypasses filename validation. A crafted filename becomes a UNC path, causing File.Exists to contact an attacker-controlled SMB server and potentially disclose NTLM credentials.
An NTLM credential exposure vulnerability in DNN Platform related to Unicode normalization affecting versions 6.0.0 through 10.0.0.
Listed as a trending/high-risk CVE affecting DNN; no additional technical details provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.