Executive brief
TeleMessage TM SGNL (Archive Signal) contains hidden functionality where the archiving backend stores cleartext copies of user messages. This contradicts the product's documentation regarding end-to-end encryption and allows for unauthorized access to message content.
Affected products
- TeleMessage TM SGNL (Archive Signal) through 2025-05-05
- TeleMessage Text Message Archiver up to (including) 2025-05-05
Timeline
- 2025-05-05: other: Vulnerability reported as being investigated by TeleMessage
- 2025-05-08: disclosed: CVE published by NVD/MITRE
- 2025-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-01: exploited: Exploited in the wild in May 2025