Unrated severityCISA KEVNVD Advisory· Published May 28, 2025· Updated Feb 26, 2026
CVE-2025-48928
CVE-2025-48928
Description
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
Affected products
1- TeleMessage/servicev5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.