TeleMessage Vulnerabilities and Affected Products
Vulnerabilities associated with archiving backend.
Products
Clear product- TM SGNL8 vulnerabilities
- service7 vulnerabilities
- archiving backend2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-47730MEDIUM | smarsh telemessage Use of Hard-coded CredentialsThe TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password. CWE-798May 8, 2025 | CVSS4.8v3.1 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
TeleMessage TM SGNL Hidden Functionality VulnerabilityThe TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025. CWE-912May 8, 2025 | CVSS1.9v3.1 | EPSS0.428% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |