CVE Vulnerabilities

CVE-2025-47729

Hidden Functionality

Published: May 08, 2025 | Modified: Nov 05, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage End-to-End encryption from the mobile phone through to the corporate archive documentation, as exploited in the wild in May 2025.

Weakness

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product’s users or administrators.

Affected Software

NameVendorStart VersionEnd Version
Text_message_archiverTelemessage*2025-05-05 (including)

Potential Mitigations

References