A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2025-48927

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

Published
2025-07-01
Modified
2026-07-31
Sources
cisa-kev

Summary

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.