CVE-2025-0479 - CVE House
Back to Database
Status published High CVE-2025-0479

Security Misconfiguration Vulnerability in CP Plus Router

Vulnerability Description

This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and compromise the targeted system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0479

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This vulnerability is reported by Shravan Singh and Karan Patel from Redfox Cyber Security

Affected Vendor

Affected Software

CP-XR-DE21-S Router
Vulnerable Versions:
DE21_S_india_hx806_1.057.043_0023

Timeline

Official Publish: January 20th, 2025
Last Modified: January 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.