CVE-2026-18931
nicheHard-coded Credentials in TMT Talassoft Industrial Management Software
Talassoft Industrial Management Software contains hard-coded credentials (CWE-798), meaning fixed, embedded credentials are shipped with the product and can be used to authenticate. Because the issue is network-exploitable with no privileges or user interaction required (CVSS 9.1), a remote attacker who can reach a vulnerable instance can use these embedded credentials to authenticate and retrieve sensitive data accessible through the product. The CVSS vector also indicates a high integrity impact, suggesting an attacker who authenticates with the hard-coded credentials may be able to modify data as well. Any organization running Talassoft Industrial Management Software from V.4 up to, but not including, V.16 is affected. There are currently no known reports of exploitation in the wild, no public proof-of-concept, and a low 0.2% EPSS probability of exploitation within 30 days.
What to do: Upgrade Talassoft Industrial Management Software to V.16 or later, which resolves this issue. Until upgraded, restrict network access to the application (no direct internet exposure; VPN or firewall rules only), and review deployments for use of the vendor's embedded hard-coded credentials, replacing them with unique credentials where the product allows. Monitor vendor and USOM advisories for updated guidance.
| TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software | from V.4 before V.16 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.