Date Posted: 2026/08/07

【Vulnerability Alert】ShengYuan|DMS+ (Non-Mobile) - Use of Hard-coded Credentials

  • Subject: 【Vulnerability Alert】ShengYuan|DMS+ (Non-Mobile) - Use of Hard-coded Credentials


  • Description:
    • Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) TWCERTCC-200-202608-00000002
    • 【ShengYuan|DMS+ (Non-Mobile) - Use of Hard-coded Credentials】(CVE-2026-18452, CVSS: 10.0) ShengYuan DMS+ (Non-Mobile) contains a Use of Hard-coded Credentials vulnerability. An unauthenticated remote attacker can exploit a fixed API KEY to obtain control of all devices with DMS+ installed.
  • Affected Platforms:
    • DMS+ (Non-Mobile) version 563 and prior
  • Recommendations:
    • Please update to version 5.64 or later
  • Reference Information:

Computer and Communication Center
Network Systems Division