VYPR

Archiving Backend

by Telemessage

CVEs (2)

  • CVE-2025-47730MedMay 8, 2025
    risk 0.31cvss 4.8epss 0.00

    The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.

  • CVE-2025-47729LowKEVMay 8, 2025
    risk 0.24cvss 1.9epss 0.00

    The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive"…