← Vulnerability feed

Vulnerability record · CVE-2025-48928 · published 28 May 2025

CVE-2025-48928: TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTP

Smarsh · Telemessage

The TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously sent over HTTP is included in that dump. This matters because credentials can be recovered from the exposed memory content, and the flaw was exploited in the wild in May 2025.

4.0 CVSS 3.1 Medium CISA KEV since 1 Jul 2025 EPSS 0.55% · top 56.1% CWE-528 · CWE-528CWE-552 · CWE-552
4.0CVSS 3.1 base score
0.55%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is confirmed exploited in the wild and listed in CISA KEV, but the CVSS score is only 4.0 (medium) with local access and limited confidentiality impact.

What it is

The TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously sent over HTTP is included in that dump. This matters because credentials can be recovered from the exposed memory content, and the flaw was exploited in the wild in May 2025.

Impact

An attacker who can reach the exposed heap or core dump content gains a previously transmitted password, enabling credential theft and possible follow-on access to the affected service.

Attack surface

The CVSS vector is local (AV:L) with no privileges and no user interaction required, so the flaw is reached through local access to the heap or dump content rather than over the network. The description notes the password was previously sent over HTTP, but the record does not specify the exact retrieval path.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-07-01, confirming exploitation in the wild, while EPSS is low at 0.00553 (44.8th percentile).

What to do

  • Apply vendor mitigations per Smarsh/TeleMessage instructions or discontinue use of the product if mitigations are unavailable, as directed by CISA KEV.
  • Stop transmitting passwords over HTTP and enforce HTTPS for all credential submission.
  • Restrict local access to the TeleMessage host and any heap or core dump files to authorized administrators only.
  • Rotate any passwords that may have been sent over HTTP to the affected service.
  • Follow BOD 22-01 guidance for cloud services where applicable.

Detection

  • Search for and monitor access to heap or core dump files associated with the TeleMessage JSP application.
  • Review HTTP traffic logs for password submissions to TeleMessage endpoints and flag any cleartext credential transmission.
  • Hunt for unexpected local access or file reads on the TeleMessage host around the May 2025 exploitation window.
  • Alert on authentication attempts using credentials that were previously transmitted over HTTP to the service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-48928 to the Known Exploited Vulnerabilities catalog on 1 July 2025 as "TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 July 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-48928 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2025-48927TeleMessage Spring Boot Actuator heap dump endpoint exposed by insecure defaultTeleMessage through 2025-05-05 ships with Spring Boot Actuator configured to expose the /heapdump endpoint. Because this is an insecure default initi…KEVEPSS 11%analysed9.8CVE-2025-48929Smarsh telemessage insufficient session expiration vulnerabilityThe TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time)…EPSS 0.32%7.5CVE-2025-48925Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the auth…EPSS 0.26%7.5CVE-2025-48926Smarsh telemessage authentication bypass via alternate path vulnerabilityThe admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numb…EPSS 0.25%7.5CVE-2025-47730Smarsh telemessage hard-coded credentials vulnerabilityThe TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app…EPSS 0.37%5.5CVE-2025-48931Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables)…EPSS 0.09%5.3CVE-2025-48930Smarsh telemessage vulnerabilityThe TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversa…EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2025-48928), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.