External risk intelligence

DMS+ Use of Hard-coded Credentials Allows Unauthenticated Device Control

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-18452

The vulnerability involves a hard-coded API key in a device management system (DMS+). Such systems are commonly deployed as network-accessible gateways or management interfaces to facilitate remote administration, making them typically reachable via the network or internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The DMS+ (Non-Mobile) system, developed by Rich Source, contains a critical vulnerability due to hard-coded credentials. This flaw allows unauthenticated attackers to leverage a fixed API key to potentially gain complete control over all installed DMS+ devices.

  • Fixed key grants full device control.
  • Impacts device management systems.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit a hard-coded API key within the DMS+ system. This allows unauthenticated remote access to a critical management API, enabling unauthorized control over all connected DMS+ devices.

  • Unauthenticated network access is required.
  • A fixed API key can be used.
  • Full device control is the risk.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated remote attackers could exploit a fixed API key in DMS+ to gain control over installed devices. This could affect all installed DMS+ devices when they are accessible remotely.

  • Device control over all DMS+ devices.
  • Exploiting a fixed API key remotely.
  • Complete loss of device security.

Operational Fix

Recommended remediation, mitigation, and detection steps

Addressing this critical vulnerability in DMS+ requires immediate action from teams responsible for device management and security. The first practical step is to inventory all DMS+ installations, assess their network exposure and business criticality, and identify the specific accountable owners for each instance. Once identified, a risk-based remediation plan can be developed, coordinating with the vendor as necessary.

  • Device management and security teams own the issue.
  • Verify DMS+ installations and network exposure first.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DMS+ by Rich Source?

DMS+ (Non-Mobile) is a device management system designed to oversee and administer hardware units. Organizations use this software as a centralized gateway to manage the configurations, operations, and security policies of multiple connected devices across their network infrastructure.

What does CWE-798 mean for CVE-2026-18452?

CWE-798 identifies a Use of Hard-coded Credentials weakness. In the context of CVE-2026-18452, this means the software contains a fixed, embedded API key that cannot be changed by the user. Because this key is standard across all installations, it acts as a permanent 'master password' that allows anyone who discovers the key to bypass authentication and gain full control over the system.

How do attackers trigger this DMS+ vulnerability?

An attacker triggers this issue by providing the known, hard-coded API key to the system's management interface. The flaw does not require the attacker to have an existing user account or perform complex steps. Notably, this vulnerability is tied strictly to the presence of the hard-coded key; it is not triggered by typical user-level actions or standard administrative functions performed with authorized credentials.

Is my DMS+ instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that DMS+ is typically deployed as a network-accessible gateway for remote administration, meaning it is often exposed to the network or the internet. If your instance is reachable from outside your internal environment, the likelihood that an attacker can reach the management interface and utilize the hard-coded key is significantly higher, placing your devices at immediate risk.

What should I do if I manage DMS+ devices?

Begin by creating a comprehensive inventory of all DMS+ instances within your environment to identify which systems are active. Once identified, evaluate the network accessibility of each device to prioritize those facing the internet. Finally, establish contact with the vendor for guidance on updates and coordinate with your internal security team to develop a remediation plan that limits access to these devices until the hard-coded credential issue is resolved.

References