CVE-2025-55443 affects Telpo MDM versions 1.4.6 through 1.4.9, where sensitive administrator credentials and MQTT server details are stored in plaintext within log files on Android devices. This critical vulnerability (CVSS 9.1) allows unauthenticated attackers with access to these logs to gain full administrative control over the MDM platform, including device shutdown, factory reset, and software installation, as well as intercept or publish device data via the MQTT server. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.6, <= 1.4.9CPE matchmatch criteria | cpe:2.3:a:telpo:telpo_mdm:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.