CVE-2025-48927: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
Freedom Coder

Freedom Coder @freedom_coder

About: love coding.

Joined:
Apr 17, 2025

CVE-2025-48927: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

Publish Date: Jul 1
0 0

CVE ID

CVE-2025-48927

Vulnerability Name

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

  • Project: TeleMessage
  • Product: TM SGNL

Date

  • Date Added: 2025-07-01
  • Due Date: 2025-07-22

Description

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

It is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue use of the product. ; https://nvd.nist.gov/vuln/detail/CVE-2025-48927

More CVEs Info

Common Vulnerabilities & Exposures (CVE) List

Comments 0 total

    Add comment