{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/dms+-non-mobile-5.63/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":10,"id":"CVE-2026-18452"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DMS+ (Non-Mobile) (5.63)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rich Source"],"content_html":"\u003cp\u003eRich Source DMS+ (Non-Mobile), a device management solution, contains a critical Use of Hard-coded Credentials vulnerability (CWE-798) tracked as CVE-2026-18452. The vulnerability resides in the application's API implementation, where a fixed, hard-coded API key is utilized for authentication purposes. This flaw allows an unauthenticated, remote attacker to bypass all authentication controls by supplying the hard-coded key in API requests. Successful exploitation grants the attacker full administrative access to the DMS+ device. Given the nature of a device management platform, this could lead to widespread system compromise, data exfiltration, and full control over connected infrastructure. This vulnerability affects all versions of DMS+ (Non-Mobile) up to and including version 5.63. Defenders should prioritize patching or restricting network access to these devices immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS base score of 10.0, indicating a critical severity level. Exploitation provides an unauthenticated remote attacker with full administrative control over the affected DMS+ devices, potentially enabling the compromise of all managed infrastructure, unauthorized data access, and the execution of arbitrary commands. Organizations utilizing DMS+ (Non-Mobile) versions 5.63 or earlier face significant risk of total device takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to the latest version of DMS+ (Non-Mobile) as provided by the vendor, Rich Source, to remediate the vulnerability associated with CVE-2026-18452.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and firewall rules to limit exposure of DMS+ management interfaces to the public internet.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs and API gateway traffic for anomalous, repetitive, or unauthorized API key usage patterns that deviate from baseline client behavior.\u003c/li\u003e\n\u003cli\u003ePerform an inventory audit of all assets to identify and isolate instances of DMS+ (Non-Mobile) version 5.63 or earlier that remain unpatched.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-31T07:36:18Z","date_published":"2026-07-31T07:36:18Z","id":"https://feed.craftedsignal.io/briefs/2026-07-dms-plus-hardcoded-creds/","summary":"Rich Source DMS+ (Non-Mobile) versions 5.63 and earlier contain a hard-coded API key allowing unauthenticated remote attackers to gain full administrative control over affected devices.","title":"Critical Hard-coded Credential Vulnerability in Rich Source DMS+ (Non-Mobile)","url":"https://feed.craftedsignal.io/briefs/2026-07-dms-plus-hardcoded-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - DMS+ (Non-Mobile) (5.63)","version":"https://jsonfeed.org/version/1.1"}