CVE-2025-3572: Intumit Smartrobot

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files on the server.

Affected products

  • Intumit Smartrobot: before 8.0.0 (fixed in 8.0.0)

Published 2025-04-14. Last modified 2026-06-17.