Executive brief
The CP Plus CP-XR-DE21-S is a 4G LTE router used for home and small-office internet connectivity. This device contains hardcoded HTTP Digest authentication credentials in its firmware that are identical across all affected devices. An attacker on the same local network can extract these credentials from the firmware and gain full administrative access to the router, allowing them to modify network settings, intercept traffic, or lock legitimate users out of their device.
Technical details
This vulnerability is a hardcoded credentials weakness in the HTTP Digest authentication mechanism of the CP Plus CP-XR-DE21-S router firmware. The root cause is the embedding of identical authentication credentials in the firmware image deployed across all devices, making them discoverable through firmware extraction and analysis. Attack vector is adjacent network (local network access required); no authentication bypass is needed since the credentials are exposed in plaintext or easily reversible form in the firmware. Successful exploitation grants an attacker administrative access to perform privileged operations on the targeted device. A patch is available: firmware version 1.057.043_0034 or later resolves this issue.
Affected products
- CP Plus CP-XR-DE21-S firmware version 1.057.043_0027 and earlier
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Patched firmware version 1.057.043_0034 released