PT-2026-6836 · Unknown · 3Dp-Manager
Denpiligrim
·
Publicado
2026-02-06
·
Atualizado
2026-02-07
·
CVE-2026-25803
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
3DP-MANAGER versions 2.0.1 and prior
Description
3DP-MANAGER, an inbound generator for 3x-ui, automatically creates an administrative account with default credentials (admin/admin) upon initial setup. An attacker with network access to the application’s login interface can exploit this to gain full administrative control, including the ability to manage VPN tunnels and system settings.
Recommendations
Update to version 2.0.2 to resolve this issue.
Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
3Dp-Manager