Impact
The software contains hard‑coded credentials that can be retrieved by an attacker. The vulnerability allows an adversary to obtain sensitive authentication information, which can in turn be used to gain unauthorized access to the industrial management system or its underlying data. This flaw amounts to a credential misuse weakness that can compromise confidentiality and potentially system integrity.
Affected Systems
Talassoft Industrial Management Software from version 4 through 15 is affected. The vendor is TMT Machine Industry and Trade Ltd. Co. Users of these releases must verify whether they are running any of these versions.
Risk and Exploitability
The CVSS base score is 9.1, indicating a high severity vulnerability. The EPSS score is not listed, and the issue is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector could be remote or local, depending on how the software is exposed, but no explicit attack path is disclosed. The vulnerability is likely exploitable if an attacker can read the application binaries or access the configuration files where the credentials reside.
OpenCVE Enrichment