CVE-2025-48928: TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability
Medium severity, CVSS 4.0. Actively exploited: in CISA KEV since 2025-07-01. EPSS: 0.6% chance of exploitation in the next 30 days.
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
Affected products
- Smarsh TeleMessage: affected versions not specified
Published 2025-05-28. Last modified 2026-06-17.