← Back to Research Blog
CRITICAL CVE-2026-18452

Critical Hard-Coded Credential Flaw in DMS+ Exposes Enterprise Networks to Unauthenticated Takeover

10.0
CRITICAL
dms+
2026-08-15

Overview

A CVSS 10.0 vulnerability in Rich Source's DMS+ (CVE-2026-18452) allows remote attackers to bypass all authentication via a hard-coded API key, enabling full device control without prior credentials. This flaw poses acute risks to enterprises and defense sector assets with exposed DMS+ deployments.


Technical Analysis

DMS+ embeds a static API key in its non-mobile version, which can be extracted from compiled binaries or runtime memory. Attackers exploit this by crafting API requests to the device's management endpoint (often accessible over HTTP/HTTPS), bypassing authentication entirely. The vulnerability is trivial to automate at scale, requiring no user interaction or network foothold. Exploitation succeeds even if default credentials are changed, as the API key remains fixed across all installations.

Enterprise & DIB Impact

Defense Industrial Base (DIB) organizations and enterprises using DMS+ for operational technology (OT) or industrial control systems (ICS) face catastrophic exposure. Attackers can exfiltrate sensitive data, disrupt operations, or deploy ransomware directly through compromised devices. The lack of authentication requirements magnifies risk for exposed IoT/OT deployments in supply chain environments.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512