The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential, as exploited in the wild in May 2025.
🚨 Marked as known exploited on May 28th, 2025 (3 days ago).
CVE ID: CVE-2025-48925
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vendor: TeleMessage
Product: service
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 14.05% (scored less or equal to compared to others)
EPSS Date: 2025-05-30 (when was this score calculated)