ZeroHour

CVE-2026-19412

moderate

Hardcoded HTTP Digest credentials in CP Plus CP-XR-DE21-S router firmware

CVSS 4.0
8.7 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-19412 is a use of hard-coded credentials (CWE-798) in the CP Plus CP-XR-DE21-S Router: the HTTP Digest authentication credentials embedded in the firmware are identical across all devices running the affected firmware. An attacker who can reach the router's administrative interface from the local (adjacent) network can extract the hardcoded credentials from the firmware and answer the Digest authentication challenge without knowing any user-configured password. Successful exploitation grants unauthorized administrative access, allowing privileged operations on the device. All CP-XR-DE21-S units running the affected firmware are affected, since the shared credentials are a property of the firmware image rather than of any individual deployment. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only a 0.2% chance of exploitation within 30 days.

What to do: Because the credentials are baked into the firmware, changing the admin password may not eliminate the risk; check with CP Plus/Aditya Infotech (and the CERT-In advisory) for a firmware update that removes or randomizes the hardcoded Digest credentials and apply it when released. Until patched, limit local network access to the router's management interface to trusted devices, keep the admin interface off WAN-facing exposure, and segment guest or IoT devices away from the router's management plane.

Affected
CP Plus CP-XR-DE21-S RouterDevices running the affected firmware; specific affected and fixed firmware version numbers were not enumerated in the advisory
Estimated exposure
moderatelikely on the order of tens of thousands of deployed units (single router model, no public scan counts) — This is an order-of-magnitude estimate based on deployment patterns: it applies to a single router model from a vendor whose devices are widely deployed in Indian home and small-business networks, and no public internet-exposure scan or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.

Weakness
CWE-798
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.