SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18452

CRITICAL · CVSS 10 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

DMS+ (Non-Mobile) by Rich Source contains a critical vulnerability due to hard-coded credentials, allowing unauthenticated remote attackers to exploit a fixed API key. This flaw enables attackers to gain full control over all installed DMS+ devices, posing significant risks to system integrity and data security. Organizations using DMS+ should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18452
Severity
CRITICAL
CVSS
10
EPSS
0.43%

Original NVD Description

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.