PT-2025-20382 · Telemessage · Telemessage Archiving Backend
Matthew Green
+1
·
Published
2025-05-08
·
Updated
2025-10-22
·
CVE-2025-47730
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TeleMessage archiving backend versions through 2025-05-05
Description
The issue concerns the acceptance of API calls from the TM SGNL (aka Archive Signal) app to request an authentication token, using hardcoded credentials. The credentials used are
logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.Recommendations
For versions through 2025-05-05, consider disabling the API endpoint that accepts authentication token requests from the TM SGNL app until a patch is available. Restrict access to the affected API endpoint to minimize the risk of exploitation. Avoid using the hardcoded credentials
logfile and enRR8UVVywXYbFkqU#QDPRkO in the affected API calls until the issue is resolved.Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telemessage Archiving Backend