SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19412

HIGH · CVSS 8.7 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The CP Plus CP-XR-DE21-S Router contains hardcoded HTTP Digest authentication credentials in its firmware, which are the same across all affected devices. This vulnerability allows an attacker with local network access to exploit these credentials, potentially gaining unauthorized administrative access and executing privileged operations on the router. Organizations using this router should prioritize remediation to prevent unauthorized access and potential network compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19412
Severity
HIGH
CVSS
8.7
EPSS
0.19%

Original NVD Description

This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized administrative access and perform privileged operations on the targeted device.