CVE-2025-48928
TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
MEDIUM · CVSS 4
⚠ CISA KEV
EPSS 0.08289
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
Sigma rules0
YARA rules0