This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware.



Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.

Project Subscriptions

Vendors Products
Cp Plus Subscribe
Cp-xr-de21-s Router Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade CP Plus CP-XR-DE21-S Router to patched firmware version 1.057.043_0034 https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin


Workaround

No workaround given by the vendor.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Title Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router
First Time appeared Cp Plus
Cp Plus cp-xr-de21-s Router
Weaknesses CWE-798
CPEs cpe:2.3:a:cp_plus:cp-xr-de21-s_router:version_1.057.043_0027_or_below:*:*:*:*:*:*:*
Vendors & Products Cp Plus
Cp Plus cp-xr-de21-s Router
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-08-28T18:24:37.115Z

Reserved: 2026-08-10T09:43:00.341Z

Link: CVE-2026-19412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T16:17:08.610

Modified: 2026-08-28T20:17:24.680

Link: CVE-2026-19412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T17:00:13Z

Weaknesses