CVE-2025-48928

CVE-2025-48928 details a critical vulnerability in TeleMessage TM SGNL, a secure messaging solution used for archiving communications.

Executive summary

CVE-2025-48928 details a critical vulnerability in TeleMessage TM SGNL, a secure messaging solution used for archiving communications. This flaw involves the "Exposure of Core Dump File to an Unauthorized Control Sphere," allowing local access to memory dump files that contain sensitive information, including passwords sent over HTTP. While the CVSS score is 4.0 (Medium severity), the context of active exploitation and inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog significantly escalates its urgency and risk.