Umbra Wiki cve cve/CVE-2025-47729
Back to wiki

CVE-2025-47729 — TeleMessage TM SGNL Hidden Functionality Vulnerability

provenance: imported · CVE: CVE-2025-47729

CVE-2025-47729: TeleMessage TM SGNL Hidden Functionality Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project TeleMessage
Product TM SGNL
Date added 2025-05-12
Due date 2025-06-02
Ransomware campaign use Unknown

Description

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

Apply mitigations per vendor instructions. Absent mitigating instructions from the vendor, discontinue use of the product. ; https://nvd.nist.gov/vuln/detail/CVE-2025-47729

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-47729
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog