CVE-2025-48928
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
0.6%
45.0th percentile
CISA KEV
Listed
Added 2025-07-01 · patch by 2025-07-22
Weakness / dates
—
Published — · modified —
Description
TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.