CVE-2025-47730 Details
Description
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.
A vulnerability in the TeleMessage archiving backend, used to archive Signal messages for U.S. government officials, has been identified. The app, which is a modified version of Signal, was found to store chat logs unencrypted, allowing an unauthorized party to access them. This issue arises from the app's integration with TeleMessage's servers, which were reportedly exposed to the public internet and accessible to the hacker. The vulnerability affects all versions of the TeleMessage archiving app through May 5, 2025.
TeleMessage has temporarily suspended all services and is investigating the security incident. However, it is unclear if or when the vulnerability will be fully addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| smarsh telemessage | <= 2025-05-05 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 22, 2025 | Initial Analysis | [email protected] |
| May 8, 2025 | New CVE Received | [email protected] |