nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-48925 CVE-2025-48925
MEDIUM
smarsh telemessage Use of Password Hash Instead of Password for Authentication
Record summary
CVE-2025-48925 has a selected CVSS score of 4.3 (medium).
Description
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 28, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
TM SGNLBrowse TeleMessage / TM SGNL | VulnCheck | Version data not supplied | |
serviceBrowse TeleMessage / serviceDefault status: unknown | CVE List | Through 2025-05-05 | affected |
References
2wired.com
https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes