SYS::ONLINE
Wasteland.
Briefs1634
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-18452 2026-07-31

CVE-2026-18452: Hard-Coded API Key in Rich Source DMS+ Rated CVSS 10.0

"According to a TWCERT advisory, a fixed, hard-coded API key in Rich Source's DMS+ (Non-Mobile) product could allow unauthenticated remote attackers to take control of installed DMS+ devices. The scope of that impact…"

According to a TWCERT advisory, a fixed, hard-coded API key in Rich Source's DMS+ (Non-Mobile) product could allow unauthenticated remote attackers to take control of installed DMS+ devices. The scope of that impact rests on the advisory's own description and has not been independently verified in the supplied data.

What Is It

CVE-2026-18452 is a Use of Hard-coded Credentials flaw (CWE-798) in DMS+ (Non-Mobile), developed by Rich Source. According to the advisory, the product ships with a fixed API key, and an unauthenticated remote attacker who obtains that key can exploit it to gain control over all installed DMS+ devices. That claim is the advisory's characterization; no proof-of-concept, technical write-up, or third-party confirmation accompanies it in the available record.

The vulnerability was published on 2026-07-31 and reported by TWCERT ([email protected]). Its NVD record is currently in "Received" status, meaning it has not yet completed NVD analysis.

Why It Matters

This carries a CVSS 3.1 base score of 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. A CVSS 4.0 secondary score from the same source is also 10.0 CRITICAL. Both scores were assigned by the reporting party rather than by NVD analysts.

As scored, every exploitability factor is worst-case: network attack vector, low attack complexity, no privileges required, and no user interaction. The scope is Changed, with High confidentiality, integrity, and availability impact, and under CVSS 4.0, High subsequent-system impact across all three as well.

The detail driving that severity is the advisory's statement that the credential is fixed, not per-device. If accurate, a single recovered key would generalize across the deployed fleet rather than compromising one target at a time. The available record does not describe how the key is stored, how readily it can be recovered, or whether network exposure of the management interface is a precondition; so the real-world barrier to exploitation is unclear.

What's Vulnerable

No affected CPE entries are listed in the NVD record.

Patch Status

The supplied source material does not include a CISA KEV entry for CVE-2026-18452; the KEV record is empty, so there is no confirmation of active exploitation and no KEV-mandated remediation deadline or required action in this data.

The NVD record likewise lists no patch, fixed version, or mitigation guidance. Exploit maturity is Not Defined. Operators should consult the TWCERT advisories below for vendor remediation details, as no fix information is present in the supplied data.

Sources