Impact
The vulnerability is a use of hard‑coded credentials (CWE‑798). An unauthenticated attacker can exploit a fixed API key to gain full control over any installed DMS+ (Non‑Mobile) device.
Affected Systems
The affected product is Rich Source DMS+ (Non‑Mobile). Versions prior to 5.64 contain the hard‑coded API key; the vendor recommends updating to 5.64 or later to remove the vulnerability.
Risk and Exploitability
The CVSS score of 10 indicates a critical flaw. The EPSS score of <1% indicates a low probability of exploitation, so the likelihood of active exploitation is currently low. The vulnerability is not listed in CISA KEV. The attack vector is unauthenticated remote via a predictable API key, meaning that any device exposed to the network is at risk if an attacker discovers the known key.
OpenCVE Enrichment