TeleMessage service exposes heap content similar to a core dump containing previously transmitted passwords. This is classified as CWE-528 (exposure of core dump file) with local attack vector, indicating the vulnerability requires local system access rather than direct internet exploitation.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2025-05-28
Added to CISA KEV: 2025-07-01 34 DAYS BETWEEN CVE AND KEV
CVE-2025-48928 is a critical security vulnerability affecting the TeleMessage service, specifically involving the exposure of sensitive information through improper handling of application memory [1] [2].
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a core dump.
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
CVE-2025-48927 TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability CVE-2025-48928 TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability…
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
We added TeleMessage TM SGNL vulnerabilities CVE-2025-48927 & CVE-2025-48928 to our Known Exploited Vulnerabilities Catalog.