top of page
perceptive_background_267k.jpg

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to ga…

Published:

31 July 2026 at 00:00:00

Alert date:

31 July 2026 at 10:00:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access

DMS+ (Non-Mobile), a device management system developed by Rich Source, contains a Use of Hard-coded Credentials vulnerability tracked as CVE-2026-18452. The vulnerability stems from a fixed API key embedded in the software that cannot be changed by users. Unauthenticated remote attackers can exploit this hard-coded API key to gain full control over all installed DMS+ devices without requiring any credentials. The attack vector is remote and requires no authentication, making it particularly severe. This type of vulnerability is a well-known security anti-pattern that exposes all deployments of the affected software simultaneously. The issue has been reported via TWCERT (Taiwan Computer Emergency Response Team). Organizations using DMS+ (Non-Mobile) should apply vendor patches or mitigations immediately. The vulnerability has been assigned a high criticality rating due to the ease of exploitation and potential for widespread impact across all installations.

Technical details

Mitigation steps:

Affected products:

DMS+ (Non-Mobile) by Rich Source

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page