CVE-2025-48925
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48925?
The severity of CVE-2025-48925 is critical due to its exploitation in the wild and reliance on insecure MD5 hashing for authentication.
How do I fix CVE-2025-48925?
To fix CVE-2025-48925, ensure you update the TeleMessage TM SGNL app to a version beyond 2025-05-05 that addresses the hashing vulnerability.
What vulnerabilities does CVE-2025-48925 exploit?
CVE-2025-48925 exploits the client-side reliance on MD5 hashing for authentication, making it susceptible to hash collisions and attacks.
Which versions of the TeleMessage TM SGNL app are affected by CVE-2025-48925?
The versions of the TeleMessage TM SGNL app up to and including 2025-05-05 are affected by CVE-2025-48925.
What type of attack can CVE-2025-48925 facilitate?
CVE-2025-48925 can facilitate man-in-the-middle attacks and unauthorized access due to weak client-side authentication.