CVE-2026-19412
Received Received - Intake

Authentication Bypass in CP Plus CP-XR-DE21-S Router

Vulnerability report for CVE-2026-19412, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: Indian Computer Emergency Response Team (CERT-In)

Description

This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cp_plus cp-xr-de21-s_router *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the CP Plus CP-XR-DE21-S Router firmware, which contains hardcoded HTTP Digest authentication credentials shared across all devices. An attacker on the local network can extract these credentials from the firmware to gain unauthorized administrative access.

Detection Guidance

Check if your CP Plus CP-XR-DE21-S Router is running the affected firmware by inspecting the device's firmware version through the admin panel or CLI. If the firmware is accessible, search for hardcoded HTTP Digest authentication credentials in the configuration files or firmware dump.

Impact Analysis

An attacker could exploit this to gain full administrative control over the router, allowing them to perform privileged operations such as changing settings, intercepting network traffic, or disabling security features.

Compliance Impact

This vulnerability could lead to unauthorized administrative access to network devices, potentially exposing sensitive data. GDPR requires protection of personal data, and HIPAA mandates secure access to health information. Unauthorized access may violate these regulations by compromising data confidentiality and integrity.

Mitigation Strategies

Immediately update the router's firmware to the latest version provided by CP Plus. If no update is available, isolate the router from the local network to prevent unauthorized access. Change all default credentials and monitor network traffic for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19412. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart