DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Please update to version 5.64 or larer.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices. | |
| Title | Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-07-31T05:54:55.052Z
Reserved: 2026-07-31T05:43:34.083Z
Link: CVE-2026-18452
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses