← Back to browse · API

CVE-2026-18452

Severity
CRITICAL
CVSS
10.0
EPSS
0.00432
Risk score
40.15
CISA KEV
No
PoC
No
Published
2026-07-31
Modified
2026-07-31
First seen
2026-08-05
Aliases
EUVD-2026-51406, GHSA-MPMJ-35XJ-3R38
Products
Rich Source:DMS+ (Non-Mobile) 0 ≤5.63
Sources
nvd CVE-2026-18452
euvd EUVD-2026-51406

Description

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

References