EXPOSURES › CVE-2025-48927
CVE-2025-48927
HIGH ⌖ ON CISA KEV · EXPLOITEDTeleMessage's TM SGNL exposed heap dump endpoint at /heapdump, allowing unauthorized access and potential remote code execution.
TeleMessage's TM SGNL had an insecure default configuration that exposed a heap dump endpoint at /heapdump, enabling attackers to potentially execute arbitrary code remotely. This exposed the system to unauthorized access and potential data breaches.
Shame score — Critical remote code execution vulnerability due to an insecure default configuration.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.