The CVE-2025-48927 vulnerability related to TeleMessage is attracting attention from hackers who continue to attempt exploitation. Experts from GreyNoise have provided insights into the current situation.
What is CVE-2025-48927?
CVE-2025-48927 is a vulnerability that allows hackers to extract data from vulnerable systems. The issue arises from the ongoing use of legacy configuration in Spring Boot Actuator.
Details and Consequences of the Vulnerability
According to GreyNoise's report, 11 IP addresses attempting to exploit the vulnerability have been recorded since April. A total of 2,009 IPs were found probing for Spring Boot Actuator endpoints.
User Protection Recommendations
Experts at GreyNoise recommend that users block malicious IP addresses and restrict access to the */heapdump* endpoint. Limiting access to Actuator endpoints is also advisable.
The CVE-2025-48927 vulnerability poses a significant threat to TeleMessage users, especially government organizations and enterprises. Protecting against potential attacks requires attention and timely measures.