Group-Office (enterprise CRM/groupware) contains a remote code execution vulnerability in the email/message/tnefAttachmentFromTempFile endpoint in versions prior to 6.8.150, 25.0.82, and 26.0.5. The implementation directly concatenates the user-controlled tmp_file parameter into an exec() call without sufficient sanitization/escaping. An authenticated attacker can inject shell metacharacters into tmp_file to achieve OS command injection, resulting in arbitrary command execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python PoC exploit plus a README. The exploit targets Group-Office (Intermesh) versions < 26.0.4 (CVE-2026-25512, CWE-78) and achieves authenticated remote command execution by abusing an OS command injection in the TNEF attachment handler endpoint /email/message/tnefAttachmentFromTempFile. Structure & flow: - README.md: vulnerability metadata (affected/fixed versions, GHSA, patch commit) and high-level description. - groupoffice_cve_2026_25512_poc.py: operational PoC that (1) logs in by POSTing to /index.php with task=login, (2) sends a GET request to /email/message/tnefAttachmentFromTempFile with tmp_file set to 'dummy.dat; {payload}; #' to inject shell commands, and (3) validates execution by parsing the returned ZIP (Content-Type application/zip) and searching for an entry containing 'rce_poc' to print its contents. Default payload writes output to /tmp/rce_poc.txt. Key capability: authenticated RCE over HTTP(S) with a user-supplied command payload; no persistence or lateral movement logic is included.
Repository contains a proof-of-concept exploit for CVE-2026-25512, an authenticated OS command injection leading to RCE in Group-Office (reported as affecting versions <= 26.0.4). The issue is in the `email/message/tnefAttachmentFromTempFile` handler where the `tmp_file` request parameter is concatenated into an `exec()` call that runs the configured TNEF extraction command, allowing shell metacharacter injection. Structure: - `README.md`: Vulnerability write-up, affected versions, vulnerable PHP snippet, and manual exploitation steps (login to obtain `security_token`, then call the vulnerable endpoint with a malicious `tmp_file`). - `poc.py`: Python exploit that (1) logs in via `index.php?r=core/auth/login` using `requests.Session()` to maintain cookies, (2) extracts `security_token` from the JSON response, (3) triggers the vulnerable endpoint `index.php?r=email/message/tnefAttachmentFromTempFile` with an injected `tmp_file` payload. Exploit behavior/capabilities: - Authenticated remote command execution by injecting `;{CMD};#` style shell syntax into `tmp_file`. - Output capture/verification: the payload writes command output to `rce.txt` and appends a unique marker; the endpoint returns a ZIP (created server-side) which the PoC parses to read `rce.txt` and confirm execution. - The PoC defaults to `CMD = "id"` but includes a commented example showing how it could be swapped for a reverse shell command, indicating easy payload customization. No additional C2 infrastructure is hardcoded beyond the local default target (`http://localhost:9090`); any reverse shell endpoint would be user-supplied by editing `CMD`.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.