EXPOSURES › CVE-2025-48928
CVE-2025-48928
HIGH ⌖ ON CISA KEV · EXPLOITEDTeleMessage's TM SGNL exposed core dumps with passwords, exploited in the wild.
TeleMessage's TM SGNL software exposed core dumps containing passwords to unauthorized users, leading to potential data breaches. This vulnerability was actively exploited in the wild.
Shame score — Serious exposure of sensitive information to unauthorized entities.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.