CERT-In Flags High-Severity Vulnerability in CP Plus Router, Users Advised to Upgrade Firmware
- Cybersecurity
- (Asia/Kolkata)
New Delhi: The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity vulnerability note for the CP Plus CP-XR-DE21-S Router, warning that the security flaw could allow an attacker on the local network to gain unauthorised administrative access to the targeted device.
The vulnerability note, CIVN-2026-0428, was originally issued on August 28, 2026, and carries a HIGH severity rating.
Affected system
- CP Plus CP-XR-DE21-S Router — firmware version 1.057.043_0027 or below
The CP Plus CP-XR-DE21-S is a 4G LTE router designed for high-speed internet connectivity and is suitable for home and small-office use.
According to CERT-In, the vulnerability exists because of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware.
An attacker with access to the local network could exploit the vulnerability by obtaining the hardcoded authentication information from the firmware.
Successful exploitation could allow the attacker to gain unauthorised administrative access and perform privileged operations on the targeted device. CERT-In said the impact could include gaining full administrative control of the device.
CERT-In recommends firmware upgrade
CERT-In has advised users to upgrade the CP Plus CP-XR-DE21-S Router to patched firmware version 1.057.043_0034.
The vulnerability is tracked as CVE-2026-19412.
The vulnerability was reported by Stalin S, Harini M, Rohit Surya A T and Reginald Alfret V.