Description
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Published: 2026-07-31
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use of hard‑coded credentials (CWE‑798). An unauthenticated attacker can exploit a fixed API key to gain full control over any installed DMS+ (Non‑Mobile) device.

Affected Systems

The affected product is Rich Source DMS+ (Non‑Mobile). Versions prior to 5.64 contain the hard‑coded API key; the vendor recommends updating to 5.64 or later to remove the vulnerability.

Risk and Exploitability

The CVSS score of 10 indicates a critical flaw. The EPSS score of <1% indicates a low probability of exploitation, so the likelihood of active exploitation is currently low. The vulnerability is not listed in CISA KEV. The attack vector is unauthenticated remote via a predictable API key, meaning that any device exposed to the network is at risk if an attacker discovers the known key.

Generated by OpenCVE AI on August 3, 2026 at 10:12 UTC.

Remediation

Vendor Solution

Please update to version 5.64 or larer.


OpenCVE Recommended Actions

  • Apply the vendor‑recommended update to version 5.64 or later.
  • Restrict network exposure of the DMS+ API by configuring firewalls or VPNs to allow only trusted internal traffic.
  • Verify that no custom API keys or passwords have been set; monitor system logs for unauthorized API access attempts.

Generated by OpenCVE AI on August 3, 2026 at 10:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Rich Source
Rich Source dms+ (non-mobile)
Vendors & Products Rich Source
Rich Source dms+ (non-mobile)

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Title Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Rich Source Dms+ (non-mobile)
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-07-31T19:25:00.663Z

Reserved: 2026-07-31T05:43:34.083Z

Link: CVE-2026-18452

cve-icon Vulnrichment

Updated: 2026-07-31T19:24:54.824Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:27.400

Modified: 2026-07-31T20:16:49.927

Link: CVE-2026-18452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:15:03Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials