CVE-2026-18452

10.0

Rich Source · DMS+ (Non-Mobile)

DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.

Executive summary

DMS+ (Non-Mobile) is vulnerable to a critical hardcoded credential flaw that permits unauthenticated attackers to hijack the device.

Vulnerability

The product utilizes hardcoded credentials (CWE-798) within its API. This allows an unauthenticated attacker to send malicious requests and gain unauthorized access to the device management functions.

Business impact

With a CVSS score of 10.0, this represents the highest level of risk. An attacker can gain full control over all deployed DMS+ devices, potentially leading to widespread operational disruption, data theft, and the use of the devices as a platform for further network attacks.

Remediation

Immediate Action: Update all instances of DMS+ (Non-Mobile) to version 5.64 or later.

Proactive Monitoring: Review API logs for unauthorized access attempts or unusual command activity that deviates from standard operational baselines.

Compensating Controls: Restrict access to the API endpoints using network level access control lists (ACLs) to ensure that only authorized internal systems can communicate with the devices.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is an extremely critical vulnerability requiring immediate attention. Administrators must update all vulnerable DMS+ devices to version 5.64 immediately to prevent potential remote exploitation and complete device takeover.

More Rich Source CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Fix documented version 5.64 per CVE record