{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T16:49:16.226","vulnerabilities":[{"cve":{"id":"CVE-2025-48929","sourceIdentifier":"cve@mitre.org","published":"2025-05-28T17:15:25.233","lastModified":"2026-06-17T09:30:30.227","vulnStatus":"Analyzed","cveTags":[{"sourceIdentifier":"cve@mitre.org","tags":["exclusively-hosted-service"]}],"descriptions":[{"lang":"en","value":"The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary."},{"lang":"es","value":"El servicio TeleMessage, hasta el 5 de mayo de 2025, implementa la autenticación a través de una credencial de larga duración (por ejemplo, no un token con un tiempo de vencimiento corto) que se puede reutilizar en una fecha posterior si un adversario la descubre, como se explotó en la naturaleza en mayo de 2025."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"TeleMessage","product":"service","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"2025-05-05","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-29T18:55:05.083280Z","id":"CVE-2025-48929","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-922"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:smarsh:telemessage:*:*:*:*:*:*:*:*","versionEndIncluding":"2025-05-05","matchCriteriaId":"44FADD39-A519-4B77-920B-5BE3A93D7D33"}]}]}],"references":[{"url":"https://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes/","source":"cve@mitre.org","tags":["Press/Media Coverage"]}]}}]}