← back
CVE-2025-47730mediumobserved exploitationCWE-798

CVE-2025-47730

35Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 4.8epss 0.4%
from disclosure to weapon
Published on NVDMay 8
VulnCheckMay 8
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
yesVulnCheck
In short

TeleMessage's archiving system accepts API requests using hardcoded credentials (a generic logfile username and a fixed password), allowing anyone with knowledge of these credentials to request authentication tokens without proper authorization.

Technical detail

The TeleMessage backend implements hardcoded credentials (CWE-798) in its API authentication mechanism, accepting requests from the TM SGNL app using a static username and password. An attacker with knowledge of these credentials can authenticate and obtain tokens, bypassing proper user identity verification and potentially accessing archived data or performing unauthorized operations.

Summary generated and translated by AI from the official description.
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N