Critical Hard-Coded Credential Flaw in DMS+ Exposes Enterprise Networks to Unauthenticated Takeover
Overview
A CVSS 10.0 vulnerability in Rich Source's DMS+ (CVE-2026-18452) allows remote attackers to bypass all authentication via a hard-coded API key, enabling full device control without prior credentials. This flaw poses acute risks to enterprises and defense sector assets with exposed DMS+ deployments.
Technical Analysis
DMS+ embeds a static API key in its non-mobile version, which can be extracted from compiled binaries or runtime memory. Attackers exploit this by crafting API requests to the device's management endpoint (often accessible over HTTP/HTTPS), bypassing authentication entirely. The vulnerability is trivial to automate at scale, requiring no user interaction or network foothold. Exploitation succeeds even if default credentials are changed, as the API key remains fixed across all installations.
Enterprise & DIB Impact
Defense Industrial Base (DIB) organizations and enterprises using DMS+ for operational technology (OT) or industrial control systems (ICS) face catastrophic exposure. Attackers can exfiltrate sensitive data, disrupt operations, or deploy ransomware directly through compromised devices. The lack of authentication requirements magnifies risk for exposed IoT/OT deployments in supply chain environments.
Recommended Actions
- Isolate DMS+ devices from internet-facing networks immediately
- conduct binary analysis to extract and rotate the hard-coded API key
- block non-essential outbound traffic from affected devices
- apply vendor-provided patches if available
- and monitor API request logs for anomalous authentication patterns
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →