CVE-2025-48931 describes a vulnerability in the TeleMessage service (including smarsh telemessage) where it uses the weak MD5 algorithm for password hashing, making it susceptible to attacks like rainbow tables. With a CVSS score of 5.5 (Medium), this local vulnerability allows an attacker with low privileges to gain high confidentiality impact with low attack complexity. While there is no known active exploitation, exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-05-05CPE matchmatch criteria | cpe:2.3:a:smarsh:telemessage:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.