CVE-2026-19412
moderateHardcoded HTTP Digest credentials in CP Plus CP-XR-DE21-S router firmware
CVE-2026-19412 is a use of hard-coded credentials (CWE-798) in the CP Plus CP-XR-DE21-S Router: the HTTP Digest authentication credentials embedded in the firmware are identical across all devices running the affected firmware. An attacker who can reach the router's administrative interface from the local (adjacent) network can extract the hardcoded credentials from the firmware and answer the Digest authentication challenge without knowing any user-configured password. Successful exploitation grants unauthorized administrative access, allowing privileged operations on the device. All CP-XR-DE21-S units running the affected firmware are affected, since the shared credentials are a property of the firmware image rather than of any individual deployment. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only a 0.2% chance of exploitation within 30 days.
What to do: Because the credentials are baked into the firmware, changing the admin password may not eliminate the risk; check with CP Plus/Aditya Infotech (and the CERT-In advisory) for a firmware update that removes or randomizes the hardcoded Digest credentials and apply it when released. Until patched, limit local network access to the router's management interface to trusted devices, keep the admin interface off WAN-facing exposure, and segment guest or IoT devices away from the router's management plane.
| CP Plus CP-XR-DE21-S Router | Devices running the affected firmware; specific affected and fixed firmware version numbers were not enumerated in the advisory |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.
- Weakness
- CWE-798
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.