The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.
References
Configurations
History
No history.
Information
Published : 2025-05-08 14:15
Updated : 2025-10-22 14:53
NVD link : CVE-2025-47730
Mitre link : CVE-2025-47730
CVE.ORG link : CVE-2025-47730
JSON object : View
Products Affected
smarsh
- telemessage
CWE
CWE-798
Use of Hard-coded Credentials
