[CIVN-2026-0428] Hardcoded Credentials Vulnerability in CP Plus Router

By Published On: August 31, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Hardcoded Credentials Vulnerability in CP Plus Router


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Systems Affected


CP Plus CP-XR-DE21-S Router – firmware version 1.057.043_0027 or below

Overview


A vulnerability has been reported in CP Plus Router, which could allow an attacker on the local network to gain unauthorized administrative access to the targeted device.


Target Audience:

End-users/ Administrators of CP Plus CP-XR-DE21-S Router.


Risk Assessment:

Unauthorized administrative access to the targeted device.


Impact Assessment:

Gain full administrative control of the targeted device.


Description


The CP Plus CP-XR-DE21-S is a 4G LTE router designed for high-speed internet connectivity, suitable for home and small-office use.


This vulnerability exists in the CP Plus Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware.


Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.


Credit


This vulnerability is reported by Stalin S, Harini M, Rohit Surya A T and Reginald Alfret V.


Solution


Upgrade CP Plus CP-XR-DE21-S Router to patched firmware version 1.057.043_0034

https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin



Vendor Information


CP-Plus

https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin


References


CP-Plus

https://cpplusworld.com/prodassets/firmware/02a50613-6182-41dc-8b7f-cd58f1e6cba5.bin


CVE Name

CVE-2026-19412




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqVkqMACgkQ3jCgcSdc

ys9ZlA//cjYsCnbZRaMKmNmqkHHOW3u3mHrQ4nBk/YXlrN5yO1w1J0JiPZqO016s

6MIh925KN5zJzFOY9KOr++4Lj+O+PkwlHN+xOvtH4e/5Hid4vcOXh9VhSC3hmT7O

Dqk+sfPJPwqWYjk60clivVBDHpnWTgZ+0XtfBpPNsxMPsLu/gGKD1YR7P8eTMBfK

XswQiZIjBS1E1CaglRqtdArxJttgBwYiA2G2NnfYeyrOUA5l3iLZeOHs/tDgNjLh

mq3yBMPmf4h0JlJKW7ID5UmTlMrJUvBryKyD3Rhf7qu+pcRXAFx1d9I9M+ysZLQj

BXWCUoRNQOIr3gWKAc3kbqPIkStMZiD0bD9wJWsHCeMc/+hi5sYHsS6qn7w6mnSe

0GI3EHyMAAveyiANhWofYFjAyZzJT+S/IboG9dyi7UVN+X3q9dQ+MK9QkNKDFHI2

eqMEwwbVY5a6+/++QauC0K7xPVFMpASflGLbNxu7QLcld2QuS5unZCsulksyf4yy

mfpPl7ui7ODQ43WceLoTxp4nV4iEKm8UCv3kQkSXlBMLi6GeNsc5fLj/OCdXgxLg

8x6mNDTqNSAoGPwnr5t2ArebPJ8/f8stx9l2YDQbFArxp2yZGRriQ4fpGlchDSE/

AvsnojJpUoOiWuJO6qrfd8ZWiyRuotil2g3bk4+Zom4NQjQp0As=

=3Fxg

—–END PGP SIGNATURE—–

Share this article