CVE-2026-25803 PUBLISHED

3DP-MANAGER Uses Hard-coded Credentials

Assigner: GitHub_M
Reserved: 05.02.2026 Published: 06.02.2026 Updated: 06.02.2026

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor denpiligrim
Product 3dp-manager
Versions
  • Version <= 2.0.1 is affected

References

Problem Types

  • CWE-798: Use of Hard-coded Credentials CWE