CVE-2026-18452
Rich Source · DMS+ (Non-Mobile)
DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.
Executive summary
DMS+ (Non-Mobile) is vulnerable to a critical hardcoded credential flaw that permits unauthenticated attackers to hijack the device.
Vulnerability
The product utilizes hardcoded credentials (CWE-798) within its API. This allows an unauthenticated attacker to send malicious requests and gain unauthorized access to the device management functions.
Business impact
With a CVSS score of 10.0, this represents the highest level of risk. An attacker can gain full control over all deployed DMS+ devices, potentially leading to widespread operational disruption, data theft, and the use of the devices as a platform for further network attacks.
Remediation
Immediate Action: Update all instances of DMS+ (Non-Mobile) to version 5.64 or later.
Proactive Monitoring: Review API logs for unauthorized access attempts or unusual command activity that deviates from standard operational baselines.
Compensating Controls: Restrict access to the API endpoints using network level access control lists (ACLs) to ensure that only authorized internal systems can communicate with the devices.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This is an extremely critical vulnerability requiring immediate attention. Administrators must update all vulnerable DMS+ devices to version 5.64 immediately to prevent potential remote exploitation and complete device takeover.