ZeroHour

CVE-2025-59689

KEVniche

Command Injection in Libraesva Email Security Gateway Exploited in the Wild

CISA: Libraesva Email Security Gateway Command Injection Vulnerability

CVSS 3.1
6.1 medium
EPSS
2%p78
Published
()
KEV added
AI analysis

CVE-2025-59689 is a command injection flaw (CWE-77) in Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7. It is triggered when the gateway processes a crafted compressed email attachment; per the CVSS vector, no privileges are required but user interaction is involved, and the injection lets an attacker run arbitrary commands with impact that extends beyond the affected component (scope change). Any organization running an affected Libraesva ESG release is in scope, with email security gateways typically sitting in the mail flow and handling untrusted inbound attachments. The flaw is being actively exploited, with public reports attributing exploitation to state-sponsored actors, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-29.

What to do: Upgrade to the fixed release for your deployed line: 5.5.7, 5.4.8, 5.2.31, 5.1.20, or 5.0.31. Because the flaw is actively exploited, including by nation-state actors, review gateway logs and compressed-attachment handling for signs of compromise after patching; organizations subject to BOD 22-01 must apply vendor mitigations or discontinue use of the product.

Affected
libraesva Email Security Gateway4.5 through 5.5.x before 5.5.7; fixed in 5.0.31 (5.0 line), 5.1.20 (5.1 line), 5.2.31 (5.2 line), 5.4.8 (5.4 line), and 5.5.7 (5.5 line)
Estimated exposure
nichelikely on the order of thousands of appliance deployments worldwide (exact count unknown) — Libraesva is a small, specialized email-security appliance vendor deployed per organization rather than at consumer or mass-hosting scale, so a low-thousands installed base is a reasonable estimate, though no public install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

CISA Known Exploited Vulnerability
Affected
Libraesva Email Security Gateway
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
libraesva
Products
email security gateway
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news