This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware.
Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device. | |
| Title | Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router | |
| First Time appeared |
Cp Plus
Cp Plus cp-xr-de21-s Router |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:cp_plus:cp-xr-de21-s_router:version_1.057.043_0027_or_below:*:*:*:*:*:*:* | |
| Vendors & Products |
Cp Plus
Cp Plus cp-xr-de21-s Router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published: 2026-08-28T13:39:47.514Z
Updated: 2026-08-28T18:24:37.115Z
Reserved: 2026-08-10T09:43:00.341Z
Link: CVE-2026-19412
Updated: 2026-08-28T18:24:29.786Z
Status : Deferred
Published: 2026-08-28T16:17:08.610
Modified: 2026-09-01T21:08:51.950
Link: CVE-2026-19412
No data.