CVE-2025-47730 describes a critical hardcoded credential vulnerability in the TeleMessage archiving backend, specifically impacting Smarsh TeleMessage products. The vulnerability allows unauthenticated attackers to request an authentication token by using fixed credentials (username "logfile" and password "enRR8UVVywXYbFkqU#QDPRkO") when making API calls from the TM SGNL app. With a CVSS score of 7.5 (HIGH), this flaw presents a significant risk of unauthorized access to sensitive information due to its network-based attack vector and low attack complexity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-05-05CPE matchmatch criteria | cpe:2.3:a:smarsh:telemessage:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.