CVE-2026-19412

8.7

CP Plus · CP-XR-DE21-S Router

The CP Plus CP-XR-DE21-S router contains hardcoded authentication credentials in its firmware, allowing unauthenticated attackers on the local network to gain administrative access.

Executive summary

A critical security flaw in the CP Plus CP-XR-DE21-S router firmware allows unauthenticated attackers to gain full administrative control due to the presence of hardcoded credentials.

Vulnerability

The device uses hardcoded HTTP Digest credentials (CWE-798) that are identical across all units. This flaw allows an unauthenticated attacker with local network access to bypass authentication and execute administrative functions.

Business impact

The exploitation of this vulnerability permits full administrative control over the router, which can lead to complete compromise of network traffic, unauthorized device configuration changes, and potential pivot points into the internal network. With a CVSS score of 8.7, this vulnerability represents a high risk to organizational network integrity and operational continuity.

Remediation

Immediate Action: Upgrade the CP Plus CP-XR-DE21-S router firmware to version 1.057.043_0034 or higher immediately to remove the hardcoded credentials.

Proactive Monitoring: Review network access logs for unusual administrative logins or unauthorized configuration changes originating from internal network segments.

Compensating Controls: Implement strict network segmentation and restrict management interface access to authorized administrative IP addresses via firewall rules until the update can be applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity and the nature of hardcoded credentials, administrators must prioritize patching this device to the specified version. Failure to update leaves the infrastructure vulnerable to full administrative takeover by any actor with local network access. Proceed with the firmware upgrade immediately to mitigate this critical exposure.

Sources

Originally found and disclosed by This vulnerability is reported by a team of security researchers including Stalin S, Harini M, Rohit Surya A T and Regin, per the CVE Program record.