CVE-2026-18452

Rich Source · DMS+ (Non-Mobile)

DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.

Executive summary

DMS+ (Non-Mobile) is vulnerable to a critical hardcoded credential flaw that permits unauthenticated attackers to hijack the device.

Vulnerability

The product utilizes hardcoded credentials (CWE-798) within its API. This allows an unauthenticated attacker to send malicious requests and gain unauthorized access to the device management functions.

Business impact

With a CVSS score of 10.0, this represents the highest level of risk. An attacker can gain full control over all deployed DMS+ devices, potentially leading to widespread operational disruption, data theft, and the use of the devices as a platform for further network attacks.

Remediation

Immediate Action: Update all instances of DMS+ (Non-Mobile) to version 5.64 or later.

Proactive Monitoring: Review API logs for unauthorized access attempts or unusual command activity that deviates from standard operational baselines.

Compensating Controls: Restrict access to the API endpoints using network level access control lists (ACLs) to ensure that only authorized internal systems can communicate with the devices.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is an extremely critical vulnerability requiring immediate attention. Administrators must update all vulnerable DMS+ devices to version 5.64 immediately to prevent potential remote exploitation and complete device takeover.