该漏洞存在于 CP Plus CP-XR-DE21-S 路由器中,原因是固件中硬编码了 HTTP Digest 认证凭据,且这些凭据在所有运行受影响固件的设备之间完全相同。拥有本地网络访问权限的攻击者可以通过从固件中提取这些硬编码的认证信息来利用此漏洞。 成功利用该漏洞后,攻击者可获得未授权的行政访问权限,并能在目标设备上执行特权操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CP Plus | CP-XR-DE21-S Router | version 1.057.043_0027 or below |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CP Plus | CP-XR-DE21-S Router | version 1.057.043_0027 or below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet