Skip to content
COOEY

EXPOSURES › CVE-2025-48927

CVE-2025-48927

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-07-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-48927 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 exploited-in-wildunpatchedrce

TeleMessage's TM SGNL exposed heap dump endpoint at /heapdump, allowing unauthorized access and potential remote code execution.

TeleMessage's TM SGNL had an insecure default configuration that exposed a heap dump endpoint at /heapdump, enabling attackers to potentially execute arbitrary code remotely. This exposed the system to unauthorized access and potential data breaches.

Shame score — Critical remote code execution vulnerability due to an insecure default configuration.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.