CVE-2025-55443

CRITICAL

Telpo MDM <1.4.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with access to these logs to: 1. Authenticate to the MDM web platform to execute administrative operations (device shutdown/factory reset/software installation); 2. Connect to the MQTT server to intercept/publish device data.

Scores

CVSS v3 9.1
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
telpo/telpo_mdm 1.4.6 - 1.4.9
Published Aug 26, 2025
Tracked Since Feb 18, 2026