CVE-2026-18452
CRITICALDMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Published: 7/31/2026Modified: 7/31/2026