Skip to content

Hacker Exploits TeleMessage App Vulnerability

Ongoing Exploitation Attempts on TeleMessage Vulnerability Detected

  • 11 IP addresses have attempted to exploit the CVE-2025-48927 vulnerability since April.
  • Over the last 90 days, a total of 2,009 IPs searched for Spring Boot Actuator endpoints.
  • The vulnerability allows data extraction from systems due to an unsecured diagnostic /heapdump endpoint.
  • TeleMessage, acquired by Smarsh in 2024, previously suspended services after a security breach in May.
  • GreyNoise advises users to block malicious IPs and restrict access to vulnerable endpoints.

The ongoing exploitation attempts on the TeleMessage app highlight significant risks for its users, particularly government organizations and enterprises that rely on secure communications. With over $2.17 billion stolen in crypto-related thefts this year alone, vigilance is crucial against such vulnerabilities.

As of now, the TeleMessage vulnerability remains a critical concern for users, especially given the reported attempts by multiple IP addresses to exploit it since April.(Source)

Share