← Vulnerability feed

Vulnerability record · CVE-2025-48927 · published 28 May 2025

CVE-2025-48927: TeleMessage Spring Boot Actuator heap dump endpoint exposed by insecure default

Smarsh · Telemessage

TeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initialization, the endpoint is reachable without authentication and can leak the contents of the Java heap. The record states it was exploited in the wild in May 2025.

5.3 CVSS 3.1 Medium CISA KEV since 1 Jul 2025 EPSS 11% · top 4.2% CWE-1188 · Insecure default initialization
5.3CVSS 3.1 base score
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high EPSS percentile, though the direct confidentiality impact is rated medium.

What it is

TeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initialization, the endpoint is reachable without authentication and can leak the contents of the Java heap. The record states it was exploited in the wild in May 2025.

Impact

An unauthenticated attacker can download a heap dump and extract secrets, credentials, tokens or other sensitive in-memory data. This can enable further compromise of the TeleMessage service and connected systems.

Attack surface

Reachable over the network via the exposed /heapdump URI on the TeleMessage service; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the vector and description.

Exploitation

CISA added it to KEV on 2025-07-01 with a due date of 2025-07-22, and the description states it was exploited in the wild in May 2025. EPSS 30-day probability is 0.11104 (95.7th percentile), indicating elevated likelihood.

What to do

  • Apply vendor mitigations or upgrade TeleMessage to a version that does not expose the heap dump endpoint; if no fix is available, discontinue use per CISA guidance.
  • Disable or restrict Spring Boot Actuator endpoints, especially /heapdump, and require authentication/authorization for management endpoints.
  • Block external access to management/actuator paths at the network edge or reverse proxy.
  • Rotate any credentials, tokens or keys that may have been present in the Java heap.
  • Monitor for and investigate any prior access to /heapdump.

Detection

  • Search web/proxy/access logs for requests to /heapdump or other Spring Boot Actuator endpoints.
  • Alert on large outbound responses from management endpoints or unusual downloads from the TeleMessage service.
  • Review TeleMessage/Spring Boot configuration for exposed actuator endpoints and verify authentication is enforced.
  • Hunt for post-exploitation use of credentials or tokens that may have been extracted from heap dumps.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-48927 to the Known Exploited Vulnerabilities catalog on 1 July 2025 as "TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 July 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-48927 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed9.8CVE-2025-48929Smarsh telemessage insufficient session expiration vulnerabilityThe TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time)…EPSS 0.32%7.5CVE-2025-48925Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the auth…EPSS 0.26%7.5CVE-2025-48926Smarsh telemessage authentication bypass via alternate path vulnerabilityThe admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numb…EPSS 0.25%7.5CVE-2025-47730Smarsh telemessage hard-coded credentials vulnerabilityThe TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app…EPSS 0.37%5.5CVE-2025-48931Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables)…EPSS 0.09%5.3CVE-2025-48930Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversa…EPSS 0.13%9.8CVE-2023-27524Apache Superset default SECRET_KEY allows session forgery and auth bypassApache Superset versions up to and including 2.0.1 ship with a default SECRET_KEY that, if left unchanged, lets an attacker forge signed session cook…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2025-48927), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.