Executive brief
Talassoft is industrial management software used to control and monitor manufacturing operations. A cross-site request forgery (CSRF) vulnerability allows attackers to trick authenticated users into performing unintended actions—such as changing system configurations, halting production, or modifying access controls—by visiting a malicious webpage or clicking a crafted link while logged in.
Technical details
The vulnerability is a cross-site request forgery (CSRF) flaw in Talassoft Industrial Management Software versions 4 through 15. CSRF exploits leverage the authenticated session of a logged-in user to perform unauthorized actions without the user's knowledge or consent. An attacker crafts a malicious webpage or email link that, when clicked by an authorized user, sends forged requests to the Talassoft application to perform sensitive operations. No special authentication or network privileges beyond the ability to trick a user into clicking a link are required. The issue affects all versions from V.4 before V.16; patched versions are available in V.16 and later.
Affected products
- TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software V.4 to V.15
Timeline
- 2026-09-01: disclosed