← Terug naar overzicht

A Use of Hard-coded Credentials vulnerability has been identified in TMT Machine Industry and Trade Ltd. Co.'s Talassoft Industrial Management Software. The vulnerability allows attackers to retrieve embedded sensitive data through hardcoded credentials present in the software. Affected versions range from V.4 through versions prior to V.16. The issue is tracked as CVE-2026-18931 and was disclosed via the Turkish cybersecurity authority siberguvenlik.gov.tr. Hard-coded credentials represent a significant security risk as they cannot be changed by end users and can be exploited by anyone who discovers them. Organizations using affected versions of Talassoft should upgrade to V.16 or later to mitigate this risk.

Affected products

  • Talassoft Industrial Management Software V.4 through before V.16

Related CVE's

  • CVE-2026-18931

Categories

  • Critical Infrastructure
  • Enterprise Applications
  • Identity & Access