CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-18452 — DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v...
·Source: NIST NVD
Updated:
Executive Summary
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Analysis
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices. CVSS Score: 10. Published: 2026-07-31T07:16:27.400.