Date Posted: 2026/08/07
【Vulnerability Alert】ShengYuan|DMS+ (Non-Mobile) - Use of Hard-coded Credentials
- Subject: 【Vulnerability Alert】ShengYuan|DMS+ (Non-Mobile) - Use of Hard-coded Credentials
- Description:
- Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) TWCERTCC-200-202608-00000002
- 【ShengYuan|DMS+ (Non-Mobile) - Use of Hard-coded Credentials】(CVE-2026-18452, CVSS: 10.0) ShengYuan DMS+ (Non-Mobile) contains a Use of Hard-coded Credentials vulnerability. An unauthenticated remote attacker can exploit a fixed API KEY to obtain control of all devices with DMS+ installed.
- Affected Platforms:
- DMS+ (Non-Mobile) version 563 and prior
- Recommendations:
- Please update to version 5.64 or later
- Reference Information:
Computer and Communication Center
Network Systems Division