๐Ÿ” CVE Alert

CVE-2026-19412

UNKNOWN 0.0

Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.

CWE CWE-798
Vendor cp plus
Product cp-xr-de21-s router
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for cp plus cp-xr-de21-s router

Be the first to know when new unknown vulnerabilities affecting cp plus cp-xr-de21-s router are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CP Plus / CP-XR-DE21-S Router
version 1.057.043_0027 or below

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cert-in.org.in: https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0428

Credits

This vulnerability is reported by a team of security researchers including Stalin S, Harini M, Rohit Surya A T and Reginald Alfret V.