Executive brief
The XING CPTrans-ME-X is a communication adapter used in karaoke systems to enable network connectivity. A password is embedded directly in the device firmware, allowing anyone with knowledge of this credential to gain unauthorized administrative access to the device and potentially control or modify its operation.
Technical details
This vulnerability is a hard-coded password weakness (CWE-259) where a static credential is embedded in the firmware of the CPTrans-ME-X device. An attacker with network access to the administrative port can authenticate using this embedded password without authorization. The vulnerability has a CVSS 3.0 score of 9.8 (network-accessible, no authentication required, and leads to high impact on confidentiality, integrity, and availability). Firmware versions prior to 1.8.1.17 are affected. The vendor released a firmware update via FOTA (Firmware Over-The-Air) in April 2026 that disables the administrative port in initial configuration and restricts available commands.
Affected products
- XING CPTrans-ME-X prior to 1.8.1.17
Timeline
- 2026-09-04: disclosed
- 2026-04: patched: Firmware update via FOTA released in April 2026