Description
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware.



Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Published: 2026-08-28
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is caused by hardcoded HTTP Digest authentication credentials embedded in the firmware of the CP Plus CP-XR-DE21-S Router. Because the same credentials are used on every device with the affected firmware, an attacker who can reach the router from the local network can extract them and gain administrative privileges. The flaw allows the attacker to perform any privileged operation on the device, thereby compromising confidentiality, integrity and availability of network functions managed by the router.

Affected Systems

Affected devices are CP Plus CP-XR-DE21-S Routers running firmware versions 1.057.043_0027 or earlier. The vendor lists the affected CPE as cpe:2.3:a:cp_plus:cp-xr-de21-s_router:version_1.057.043_0027_or_below. Updating to firmware 1.057.043_0034 eliminates the hardcoded credentials.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity for this flaw. EPSS information is not available, and the vulnerability does not appear in the CISA KEV catalog. The attack is likely local: an attacker must have access to the local network to read the firmware or tokens and standard HTTP Digest parsing to retrieve the credentials. Once the attacker has the credentials, they can log in as administrator and control the router.

Generated by OpenCVE AI on August 28, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Upgrade CP Plus CP-XR-DE21-S Router to patched firmware version 1.057.043_0034 https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin


OpenCVE Recommended Actions

  • Upgrade firmware to 1.057.043_0034.
  • Restrict local network access to the router and isolate management interfaces.
  • Monitor device logs for unauthorized login attempts and enforce strong unique credentials.

Generated by OpenCVE AI on August 28, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Title Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router
First Time appeared Cp Plus
Cp Plus cp-xr-de21-s Router
Weaknesses CWE-798
CPEs cpe:2.3:a:cp_plus:cp-xr-de21-s_router:version_1.057.043_0027_or_below:*:*:*:*:*:*:*
Vendors & Products Cp Plus
Cp Plus cp-xr-de21-s Router
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cp Plus Cp-xr-de21-s Router
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-08-28T18:24:37.115Z

Reserved: 2026-08-10T09:43:00.341Z

Link: CVE-2026-19412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T16:17:08.610

Modified: 2026-08-28T20:17:24.680

Link: CVE-2026-19412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T17:00:13Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials