Junglewise Threat Intelligence

CVE-2026-18452: Rich Source DMS+ hard-coded API key

CVE-2026-18452 · Severity: critical · CVSS 10 · Published 2026-07-31

Executive brief

Rich Source DMS+ (Non-Mobile), a device management system, contains a critical security flaw where a fixed, universal API key is used for authentication. An unauthorized person can use this hard-coded key to remotely take full control of any installed DMS+ device. This could lead to complete service disruption, unauthorized access to managed systems, and potential data breaches across all affected hardware.

Technical details

The vulnerability (CWE-798) exists in Rich Source DMS+ (Non-Mobile) versions 5.63 and earlier due to the use of a fixed, hard-coded API key. This allows an unauthenticated remote attacker to bypass standard authentication mechanisms by providing the static key in API requests. Successful exploitation grants the attacker full administrative control over the affected DMS+ devices. The issue is resolved in version 5.64 and later.

Affected products

  • Rich Source DMS+ (Non-Mobile) 5.63 and earlier

Timeline

  • 2026-07-31: advisory: Advisory published by TWCERT/CC
  • 2026-07-31: patched: Version 5.64 released to address the vulnerability

References