CVE-2025-48928: TeleMessage TM SGNL
EPSS0.5%No. 1714 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV3
Same product3
| Field | Value |
|---|---|
| Vendor | TeleMessage |
| Product | TM SGNL |
| Name | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability |
| Added to KEV | 2025-07-01 |
| US federal due date | 2025-07-22 |
| Ransomware use | Unknown |
| CWE | CWE-528 |
CISA description
TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2025-48927 | TeleMessage TM SGNL | 2025-07-01 | 11.1% | Unknown |
| CVE-2025-47729 | TeleMessage TM SGNL | 2025-05-12 | 0.4% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A TeleMessage TM SGNL vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-01.