CVE-2026-18452: Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rich Source|DMS+ (Non-Mobile)to a version that resolves this vulnerability.Fixed in 5.64
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18452?
The severity of CVE-2026-18452 is rated as critical with a score of 10.
How do I fix CVE-2026-18452?
To fix CVE-2026-18452, replace hard-coded credentials with secure, dynamically generated credentials.
What does CVE-2026-18452 affect?
CVE-2026-18452 affects the Rich Source DMS+ (Non-Mobile) software.
Who can exploit CVE-2026-18452?
Unauthenticated remote attackers can exploit CVE-2026-18452.
What is the impact of CVE-2026-18452?
The impact of CVE-2026-18452 can allow attackers to gain control over all installed DMS+ devices.