PT-2025-20382 · Telemessage · Telemessage Archiving Backend

Matthew Green

+1

·

Publicado

2025-05-08

·

Atualizado

2025-10-22

·

CVE-2025-47730

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TeleMessage archiving backend versions through 2025-05-05
Description The issue concerns the acceptance of API calls from the TM SGNL (aka Archive Signal) app to request an authentication token, using hardcoded credentials. The credentials used are logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.
Recommendations For versions through 2025-05-05, consider disabling the API endpoint that accepts authentication token requests from the TM SGNL app until a patch is available. Restrict access to the affected API endpoint to minimize the risk of exploitation. Avoid using the hardcoded credentials logfile and enRR8UVVywXYbFkqU#QDPRkO in the affected API calls until the issue is resolved.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-47730

Produtos afetados

Telemessage Archiving Backend