


Perceptive Security
SOC/SIEM Consultancy

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to ga…
Published:
31 July 2026 at 00:00:00
Alert date:
31 July 2026 at 10:00:57
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
DMS+ (Non-Mobile), a device management system developed by Rich Source, contains a Use of Hard-coded Credentials vulnerability tracked as CVE-2026-18452. The vulnerability stems from a fixed API key embedded in the software that cannot be changed by users. Unauthenticated remote attackers can exploit this hard-coded API key to gain full control over all installed DMS+ devices without requiring any credentials. The attack vector is remote and requires no authentication, making it particularly severe. This type of vulnerability is a well-known security anti-pattern that exposes all deployments of the affected software simultaneously. The issue has been reported via TWCERT (Taiwan Computer Emergency Response Team). Organizations using DMS+ (Non-Mobile) should apply vendor patches or mitigations immediately. The vulnerability has been assigned a high criticality rating due to the ease of exploitation and potential for widespread impact across all installations.
Technical details
Mitigation steps:
Affected products:
DMS+ (Non-Mobile) by Rich Source
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18452
https://www.twcert.org.tw/en/cp-139-11073-de184-2.html
https://www.twcert.org.tw/tw/cp-132-11072-3a4d4-1.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
