S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-52488

8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
dnn.platform
Updated Sep 18, 2026View on NVD →
S4E scanner
highMisconfiguration~10 seconds

CVE-2025-52488 Scanner

This scanner targets the Unicode path normalization in DNN's file handling, allowing an attacker to force the server to authenticate to an attacker-controlled SMB server, leaking NTLM hashes.

Used 3.4k times · 5.9k assets checked · domain, subdomain, ipv4

CVE history: dnn.platform

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →