Skip to main content
EVULNABLE Home

CVE-2025-48928

TeleMessage — TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

CISA KEV · in the CISA KEV catalog since 2025-07-01

Overdue by 14 monthsCISA KEVActively Exploited

What EVULNABLE says

Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

MeasureValueSource
CVSS base score 4.0 NVD
FIRST EPSS 0.006 (44.2nd pctl) FIRST
Actively exploited Confirmed CISA KEV
Ransomware campaign use Unknown or none CISA KEV
CISA remediation deadline 2025-07-22 — Overdue by 14 months CISA KEV

What CISA says to do

  • It is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue use of the product
  • nvd.nist.gov/…/CVE-2025-48928 ↗

The primary records

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.

Where this sits

CVE-2025-48928 is one of the entries ranked on the priority feed and in the non-Microsoft advisories.