Description
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware.



Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Published: 2026-08-28
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade CP Plus CP-XR-DE21-S Router to patched firmware version 1.057.043_0034 https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Title Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router
First Time appeared Cp Plus
Cp Plus cp-xr-de21-s Router
Weaknesses CWE-798
CPEs cpe:2.3:a:cp_plus:cp-xr-de21-s_router:version_1.057.043_0027_or_below:*:*:*:*:*:*:*
Vendors & Products Cp Plus
Cp Plus cp-xr-de21-s Router
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cp Plus Cp-xr-de21-s Router
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-08-28T18:24:37.115Z

Reserved: 2026-08-10T09:43:00.341Z

Link: CVE-2026-19412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T16:17:08.610

Modified: 2026-08-28T20:17:24.680

Link: CVE-2026-19412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T17:00:13Z

Weaknesses