Skip to content
COOEY

FAIL › dossier

TeleMessage

VENDOR

· dossier confidence 0%

TeleMessage's TM SGNL product suffered three high-severity security failures in 2025, including remote code execution and cleartext data exposure, all actively exploited in the wild. The company's security posture is critically compromised, requiring immediate remediation and enhanced security awareness training.

PROFILE
CategorytelecommunicationsWhat they doTeleMessage provides a telegram delivery service, offering secure messaging solutions for businesses and individuals.
SECURITY POSTURE

TeleMessage's security posture is critically compromised, with multiple high-severity vulnerabilities in its TM SGNL product exposed in 2025, including remote code execution, credential exposure, and cleartext data storage, all actively exploited in the wild.

Notable failures
  • CVE-2025-48927: RCE via exposed heap dump endpoint
  • CVE-2025-48928: Exposed core dumps with passwords
  • CVE-2025-47729: Cleartext user message storage
Patterns: repeated unpatched high-severity vulnerabilities in core messaging components; failure to secure sensitive data (credentials, messages) at rest and in transit
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-07-01 CVE-2025-48927 high TeleMessage's TM SGNL exposed heap dump endpoint at /heapdump, allowing unauthorized access and potential remote code execution.
2025-07-01 CVE-2025-48928 high TeleMessage's TM SGNL exposed core dumps with passwords, exploited in the wild.
2025-05-12 CVE-2025-47729 high TeleMessage's TM SGNL stored user messages in cleartext, creating a significant data exposure risk and actively exploited in the wild.
Open questions: TeleMessage's founding year · TeleMessage's headquarters location · TeleMessage's company size · TeleMessage's ownership structure · TeleMessage's official website
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:49:20.583052+00:00