Rich Source DMS+ (Non-Mobile) contains a critical hard-coded credentials flaw tracked as CVE-2026-18452 that allows unauthenticated remote attackers to use a fixed embedded API key to gain administrative control over affected DMS+ instances and the devices they manage. The vulnerability affects versions 5.63 and earlier and is classified as CWE-798: Use of Hard-coded Credentials.
The issue carries a CVSS v3.1 score of 9.8 with impact to confidentiality, integrity, and availability, and public reporting said exploitation requires no authentication and low attack complexity. Rich Source addressed the flaw in version 5.64, while TWCERT/CC published an advisory; no active exploitation had been reported at the time of publication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
TWCERT/CC published an advisory for CVE-2026-18452, a hard-coded credentials flaw in Rich Source DMS+ (Non-Mobile). The advisory described that affected versions up to 5.63 could be remotely compromised via a fixed API key.
Rich Source fixed a hard-coded credentials vulnerability in DMS+ (Non-Mobile) by releasing version 5.64. The flaw affected version 5.63 and earlier and allowed unauthenticated remote attackers to use a fixed API key to gain administrative control over DMS+ instances and managed devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.