Description
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery.

This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
Published: 2026-09-01
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery (CWE‑352) flaw in the Talassoft Industrial Management Software that allows an unauthenticated attacker to submit requests on behalf of a logged‑in user, potentially changing configuration, initiating unauthorized orders, or deleting assets. The flaw can be exploited without knowledge of the victim’s password and may give an attacker the same level of access as the authenticated user, leading to data loss, sabotage, or further compromise.

Affected Systems

TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software, versions older than 16 while versions 4 through 15 are specifically vulnerable. Any deployment that has not yet been upgraded to the latest release is exposed.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered medium‑high severity. The attack vector is inferred to be remote via the web interface, relying on a victim’s authenticated session. No published exploit or assault tool is linked, and the vulnerability is not listed in CISA KEV, suggesting a lower immediate exploitation probability. Nonetheless, the potential for unauthorized changes warrants a prompt response.

Generated by OpenCVE AI on September 1, 2026 at 16:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 16 or later of Talassoft Industrial Management Software
  • Implement CSRF protection by ensuring the web application requires a cryptographic token for state‑changing requests
  • Restrict administrative access by using network segmentation or firewall rules to limit exposure of the management interface

Generated by OpenCVE AI on September 1, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Tmt Machine
Tmt Machine talassoft Industrial Management Software
Vendors & Products Tmt Machine
Tmt Machine talassoft Industrial Management Software

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
Title CSRF in TMT Machine's Talassoft Industrial Management Software
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}


Subscriptions

Tmt Machine Talassoft Industrial Management Software
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-01T15:24:42.886Z

Reserved: 2026-08-04T07:52:35.364Z

Link: CVE-2026-18780

cve-icon Vulnrichment

Updated: 2026-09-01T15:24:04.115Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T15:17:13.200

Modified: 2026-09-01T21:10:38.413

Link: CVE-2026-18780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T21:39:28Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)