PT-2025-20382 · Telemessage · Telemessage Archiving Backend

Matthew Green

+1

·

Published

2025-05-08

·

Updated

2025-10-22

·

CVE-2025-47730

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TeleMessage archiving backend versions through 2025-05-05
Description The issue concerns the acceptance of API calls from the TM SGNL (aka Archive Signal) app to request an authentication token, using hardcoded credentials. The credentials used are logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.
Recommendations For versions through 2025-05-05, consider disabling the API endpoint that accepts authentication token requests from the TM SGNL app until a patch is available. Restrict access to the affected API endpoint to minimize the risk of exploitation. Avoid using the hardcoded credentials logfile and enRR8UVVywXYbFkqU#QDPRkO in the affected API calls until the issue is resolved.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-47730

Affected Products

Telemessage Archiving Backend