Junglewise Threat Intelligence

CVE-2025-47729: TeleMessage TM SGNL Hidden Functionality Vulnerability

CVE-2025-47729 · Severity: critical · CVSS 4.9 · Exploited in the wild · Published 2025-05-12

Technologies: Telemessage TM SGNL. Vendors: Telemessage.

Executive brief

TeleMessage TM SGNL (Archive Signal) contains hidden functionality where the archiving backend stores cleartext copies of user messages. This contradicts the product's documentation regarding end-to-end encryption and allows for unauthorized access to message content.

Affected products

  • TeleMessage TM SGNL (Archive Signal) through 2025-05-05
  • TeleMessage Text Message Archiver up to (including) 2025-05-05

Timeline

  • 2025-05-05: other: Vulnerability reported as being investigated by TeleMessage
  • 2025-05-08: disclosed: CVE published by NVD/MITRE
  • 2025-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-01: exploited: Exploited in the wild in May 2025

Related threats