ZeroHour

CVE-2026-18931

niche

Hard-coded Credentials in TMT Talassoft Industrial Management Software

CVSS 3.1
9.1 critical
EPSS
<1%p14
Published
()
Modified
AI analysis

Talassoft Industrial Management Software contains hard-coded credentials (CWE-798), meaning fixed, embedded credentials are shipped with the product and can be used to authenticate. Because the issue is network-exploitable with no privileges or user interaction required (CVSS 9.1), a remote attacker who can reach a vulnerable instance can use these embedded credentials to authenticate and retrieve sensitive data accessible through the product. The CVSS vector also indicates a high integrity impact, suggesting an attacker who authenticates with the hard-coded credentials may be able to modify data as well. Any organization running Talassoft Industrial Management Software from V.4 up to, but not including, V.16 is affected. There are currently no known reports of exploitation in the wild, no public proof-of-concept, and a low 0.2% EPSS probability of exploitation within 30 days.

What to do: Upgrade Talassoft Industrial Management Software to V.16 or later, which resolves this issue. Until upgraded, restrict network access to the application (no direct internet exposure; VPN or firewall rules only), and review deployments for use of the vendor's embedded hard-coded credentials, replacing them with unique credentials where the product allows. Monitor vendor and USOM advisories for updated guidance.

Affected
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Softwarefrom V.4 before V.16
Estimated exposure
nichelikely hundreds to a few thousand installations, concentrated at industrial sites in Turkey (estimate; no public install-base data) — No public install counts or exposure scans exist for this product; it is a vertical-market industrial management application from a single Turkish vendor, typically deployed inside manufacturing networks with only a small fraction likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.

Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.