<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Rich Source - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/rich-source/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 31 Jul 2026 07:36:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/rich-source/feed.xml" rel="self" type="application/rss+xml"/><item><title>Critical Hard-coded Credential Vulnerability in Rich Source DMS+ (Non-Mobile)</title><link>https://feed.craftedsignal.io/briefs/2026-07-dms-plus-hardcoded-creds/</link><pubDate>Fri, 31 Jul 2026 07:36:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-dms-plus-hardcoded-creds/</guid><description>Rich Source DMS+ (Non-Mobile) versions 5.63 and earlier contain a hard-coded API key allowing unauthenticated remote attackers to gain full administrative control over affected devices.</description><content:encoded><![CDATA[<p>Rich Source DMS+ (Non-Mobile), a device management solution, contains a critical Use of Hard-coded Credentials vulnerability (CWE-798) tracked as CVE-2026-18452. The vulnerability resides in the application's API implementation, where a fixed, hard-coded API key is utilized for authentication purposes. This flaw allows an unauthenticated, remote attacker to bypass all authentication controls by supplying the hard-coded key in API requests. Successful exploitation grants the attacker full administrative access to the DMS+ device. Given the nature of a device management platform, this could lead to widespread system compromise, data exfiltration, and full control over connected infrastructure. This vulnerability affects all versions of DMS+ (Non-Mobile) up to and including version 5.63. Defenders should prioritize patching or restricting network access to these devices immediately.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS base score of 10.0, indicating a critical severity level. Exploitation provides an unauthenticated remote attacker with full administrative control over the affected DMS+ devices, potentially enabling the compromise of all managed infrastructure, unauthorized data access, and the execution of arbitrary commands. Organizations utilizing DMS+ (Non-Mobile) versions 5.63 or earlier face significant risk of total device takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade to the latest version of DMS+ (Non-Mobile) as provided by the vendor, Rich Source, to remediate the vulnerability associated with CVE-2026-18452.</li>
<li>Implement strict network segmentation and firewall rules to limit exposure of DMS+ management interfaces to the public internet.</li>
<li>Monitor web server logs and API gateway traffic for anomalous, repetitive, or unauthorized API key usage patterns that deviate from baseline client behavior.</li>
<li>Perform an inventory audit of all assets to identify and isolate instances of DMS+ (Non-Mobile) version 5.63 or earlier that remain unpatched.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>