CVE-2025-48925
MEDIUMDescription
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| smarsh | telemessage |
References
Frequently Asked Questions
What is CVE-2025-48925? +
How severe is CVE-2025-48925? +
What products are affected by CVE-2025-48925? +
How do I check if I'm vulnerable to CVE-2025-48925? +
Related Vulnerabilities
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other …
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An …
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb …
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as …
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive …
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.