Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade CP Plus CP-XR-DE21-S Router to patched firmware version 1.057.043_0034 https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device. | |
| Title | Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router | |
| First Time appeared |
Cp Plus
Cp Plus cp-xr-de21-s Router |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:cp_plus:cp-xr-de21-s_router:version_1.057.043_0027_or_below:*:*:*:*:*:*:* | |
| Vendors & Products |
Cp Plus
Cp Plus cp-xr-de21-s Router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-08-28T18:24:37.115Z
Reserved: 2026-08-10T09:43:00.341Z
Link: CVE-2026-19412
No data.
Status : Received
Published: 2026-08-28T16:17:08.610
Modified: 2026-08-28T20:17:24.680
Link: CVE-2026-19412
No data.
OpenCVE Enrichment
Updated: 2026-08-28T17:00:13Z