Description
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Please update to version 5.64 or larer.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices. | |
| Title | Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-07-31T19:25:00.663Z
Reserved: 2026-07-31T05:43:34.083Z
Link: CVE-2026-18452
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T19:00:10Z
Weaknesses
-
CWE-798
Use of Hard-coded Credentials