Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please update to version 5.64 or larer.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rich Source
Rich Source dms+ (non-mobile) |
|
| Vendors & Products |
Rich Source
Rich Source dms+ (non-mobile) |
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices. | |
| Title | Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-07-31T19:25:00.663Z
Reserved: 2026-07-31T05:43:34.083Z
Link: CVE-2026-18452
Updated: 2026-07-31T19:24:54.824Z
Status : Received
Published: 2026-07-31T07:16:27.400
Modified: 2026-07-31T20:16:49.927
Link: CVE-2026-18452
No data.
OpenCVE Enrichment
Updated: 2026-08-03T10:15:03Z