CVE-2025-48925
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.26%
- CWE
- CWE-836
- Published
- 2025-05-28
- Last modified
- 2026-03-13
Affected products
- TeleMessage service
Weakness type
Related vulnerabilities
- CVE-2026-44736 — OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
- CVE-2026-9222 — Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
- CVE-2026-40103 — Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
- CVE-2019-25552 — CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
- CVE-2025-64471 — A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability...
- CVE-2025-62618 — ELOG file upload stored XSS
- CVE-2025-52543 — Login to the application services using only the password hash
- CVE-2023-39546 — CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe...