← Browse

CVE-2025-48928

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
0.6%
45.0th percentile
CISA KEV
Listed
Added 2025-07-01 · patch by 2025-07-22
Weakness / dates
Published — · modified —

Timeline

Description

TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.

Official: NVD · CVE.org