PT-2025-23100 · Unknown · Telemessage
Publicado
2025-05-28
·
Atualizado
2025-10-22
·
CVE-2025-48925
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TeleMessage service through 2025-05-05
Description
The issue concerns the TeleMessage service relying on client-side MD5 hashing for authentication credentials. This has been exploited in the wild. The service accepts the hash as the authentication credential, which is a security concern.
Recommendations
For versions through 2025-05-05, consider disabling the MD5 hashing authentication mechanism until a more secure method is implemented. Restrict access to the TeleMessage service to minimize the risk of exploitation. Avoid using the MD5 hashed credentials in authentication processes until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Telemessage