CVE-2025-47729
TeleMessage TM SGNL Hidden Functionality Vulnerability
Description
CVE-2025-47729 is a vulnerability in TeleMessage TM SGNL (also known as Archive Signal), a messaging archiving product, where the backend stores cleartext copies of messages despite documentation claiming end-to-end encryption. This hidden functionality vulnerability means that messages archived through TM SGNL are accessible in plaintext on the TeleMessage archiving servers, contradicting the product's stated security guarantees. Although rated with a low CVSS v3.1 base score of 1.9, this vulnerability was exploited in the wild in May 2025 and CISA has added CVE-2025-47729 to the Known Exploited Vulnerabilities catalog with a remediation deadline of June 2, 2025. The EPSS score of 2.5% at the 85th percentile indicates significant exploitation probability.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:NOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| telemessage | text message archiver | <= 2025-05-05 |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
References
- https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/(Press/Media Coverage)
- https://news.ycombinator.com/item?id=43909220(Press/Media Coverage)
- https://www.theregister.com/2025/05/05/telemessage_investigating/(Press/Media Coverage)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47729(US Government Resource)
Weakness Type
CWE-912: Hidden Functionality
CVE-2025-47729 is classified under CWE-912, Hidden Functionality. This weakness occurs when software contains functionality that is not documented and is not accessible through the normal user interface, which may introduce security risks. In TeleMessage TM SGNL, the archiving backend retains cleartext copies of messages despite the product being marketed as providing end-to-end encryption from the mobile device to the corporate archive. This undocumented behavior creates a significant trust violation, as users and organizations rely on the stated encryption guarantees.
Learn more: CWE-912 — Hidden Functionality
Impact Analysis
Despite the low CVSS v3.1 score of 1.9, the real-world impact of CVE-2025-47729 is substantial when considered in context. The technical score reflects the specific attack vector requirements: local access (AV:L), high complexity (AC:H), high privileges (PR:H), and limited confidentiality impact within the CVSS framework. However, the core issue is that an archiving backend designed for sensitive government and enterprise communications stores messages in cleartext, directly contradicting claims of end-to-end encryption. This means any actor with access to the TeleMessage backend infrastructure, whether through compromise, insider access, or legal compulsion, can read archived messages that users believed were encrypted. For organizations that deployed TM SGNL under the assumption of end-to-end encrypted archiving, this vulnerability represents a fundamental breach of trust, with potential exposure of highly sensitive communications including those of government officials. The exploitation in the wild in May 2025 and subsequent media coverage confirmed that the cleartext storage was actively accessed by unauthorized parties.
Exploit Maturity
CVE-2025-47729 was actively exploited in the wild in May 2025, as confirmed by CISA's addition to the Known Exploited Vulnerabilities catalog on May 12, 2025. The exploitation gained significant public attention, with coverage from multiple major technology publications documenting the breach of TeleMessage's archiving infrastructure. The EPSS score of 2.5% at the 85th percentile is notably high for a vulnerability with a CVSS base score of only 1.9, reflecting the gap between the theoretical scoring model and real-world exploitation interest driven by the high-profile nature of the affected product and its user base. No traditional exploit code is required; the vulnerability is inherent in the system architecture that stores messages in cleartext rather than in encrypted form.
Remediation
-
Discontinue use of TeleMessage TM SGNL for archiving sensitive communications until the vendor provides verifiable evidence that the cleartext storage issue has been resolved. CISA recommends applying mitigations per vendor instructions or discontinuing use if mitigations are unavailable.
-
Assess exposure scope by determining which users and communications were archived through TM SGNL. Assume all archived messages were stored in cleartext and may have been accessible to unauthorized parties.
-
Migrate to an alternative secure archiving solution that has been independently audited to verify end-to-end encryption claims. Ensure any replacement product provides verifiable encryption at rest for archived messages.
-
Conduct a forensic review of communications that may have been exposed. For organizations handling classified or regulated data, initiate appropriate incident response and notification procedures based on the sensitivity of the exposed communications.
-
Implement procurement security requirements that mandate independent security audits and encryption verification for messaging and archiving products, particularly those claiming end-to-end encryption capabilities.
Technical Details
CVE-2025-47729 concerns a hidden functionality weakness (CWE-912) in the TeleMessage archiving backend for TM SGNL (Archive Signal). The CVSS v3.1 vector CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N reflects a technically narrow attack surface requiring local access with high privileges and high complexity, with only low confidentiality impact in the formal scoring model. However, the vulnerability's significance lies in its architectural nature: TeleMessage's documentation states that messages are end-to-end encrypted from the mobile phone through to the corporate archive, but the backend infrastructure through at least May 5, 2025, stored cleartext copies of these messages. This discrepancy means the encryption either terminates before the archive stage or is decrypted at the backend for storage, fundamentally undermining the security model. The vulnerability does not require a traditional exploit; any access to the backend storage infrastructure exposes message content that should be encrypted. The product is used by government agencies and enterprises for regulatory compliance archiving of Signal messages, making the trust violation particularly consequential.
Frequently Asked Questions
Is CVE-2025-47729 being actively exploited?
Yes. CVE-2025-47729 was exploited in the wild in May 2025, leading to unauthorized access to cleartext archived messages. CISA added it to the KEV catalog on May 12, 2025, with a remediation deadline of June 2, 2025.
What products are affected by CVE-2025-47729?
TeleMessage TM SGNL (also known as Archive Signal) through May 5, 2025, is affected. This is a messaging archiving product that captures and stores Signal messages for regulatory compliance purposes.
How do I fix CVE-2025-47729?
CISA recommends discontinuing use of TM SGNL until the vendor provides verified mitigations. Organizations should assess exposure, assume all archived messages were stored in cleartext, and migrate to independently audited archiving solutions.
How severe is CVE-2025-47729?
While the CVSS score is only 1.9 (Low), the real-world severity is much higher for organizations that relied on TM SGNL's end-to-end encryption claims. The vulnerability means archived messages were stored in cleartext, potentially exposing highly sensitive communications. The EPSS score at the 85th percentile reflects significant exploitation interest.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.