EXPOSURES › CVE-2025-47729
CVE-2025-47729
HIGH ⌖ ON CISA KEV · EXPLOITEDTeleMessage's TM SGNL stored user messages in cleartext, creating a significant data exposure risk and actively exploited in the wild.
TM SGNL's archiving backend stored messages in cleartext, exposing sensitive user data. This failure represents a severe compliance risk for DIB organizations using the product, potentially violating CMMC and NIST 800-171 requirements. Organizations should immediately assess their use of TM SGNL and implement mitigating controls or consider alternative solutions.
Shame score — Storing sensitive user data in cleartext is a fundamental security failure, especially given active exploitation, demonstrating significant negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.