CVE-2025-48928: TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability
TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48928?
CVE-2025-48928 is considered a critical vulnerability due to the exposure of sensitive information including passwords.
How do I fix CVE-2025-48928?
To mitigate CVE-2025-48928, upgrade the TeleMessage service to a version released after May 5, 2025.
What kind of data is exposed in CVE-2025-48928?
CVE-2025-48928 potentially exposes passwords that have been transmitted over HTTP.
Who is affected by CVE-2025-48928?
Users of the TeleMessage service up to version 2025-05-05 are affected by CVE-2025-48928.
Is exploitation of CVE-2025-48928 currently happening?
Yes, CVE-2025-48928 has been actively exploited in the wild since May 2025.