netVigilance Vulnerability intelligence since 2004
CVE-2025-48927 · netVigilance record NV25-0133

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default

past due

What to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA deadline 2025-07-22 · passed 1 year 1 month ago · applies to US federal civilian agencies; used elsewhere as a reference SLA

What happened

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

Who is affected

TeleMessage TM SGNL. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.

Weakness class: CWE-1188.

Timeline

  1. Added to CISA KEVExploitation in the wild confirmed by CISA
  2. CISA remediation deadlinepassed 1 year 1 month ago

Sources