Skip to content
COOEY

FAIL › dossier

TM SGNL

PRODUCT

· dossier confidence 0%

TM SGNL is a TeleMessage product with a critically weak security posture, suffering from multiple high-severity vulnerabilities in 2025 that were actively exploited in the wild, including remote code execution and cleartext data storage.

PROFILE
CategorytelecommunicationsWhat they doTM SGNL is a TeleMessage product for secure messaging and signaling.
SECURITY POSTURE

The security posture is critically weak, evidenced by multiple high-severity vulnerabilities in 2025 that were actively exploited in the wild, including remote code execution, exposure of sensitive dumps, and cleartext data storage.

Notable failures
  • CVE-2025-48927: exposed heap dump endpoint allowing RCE
  • CVE-2025-48928: exposed core dumps with passwords exploited in the wild
  • CVE-2025-47729: stored user messages in cleartext exploited in the wild
Patterns: exposed sensitive system dumps; cleartext data storage; unpatched high-severity RCEs
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-07-01 CVE-2025-48927 high TeleMessage's TM SGNL exposed heap dump endpoint at /heapdump, allowing unauthorized access and potential remote code execution.
2025-07-01 CVE-2025-48928 high TeleMessage's TM SGNL exposed core dumps with passwords, exploited in the wild.
2025-05-12 CVE-2025-47729 high TeleMessage's TM SGNL stored user messages in cleartext, creating a significant data exposure risk and actively exploited in the wild.
Open questions: What is the exact founding date of TeleMessage? · What is the headquarters location of TeleMessage? · What is the current ownership structure of TeleMessage?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:48:50.351772+00:00