PT-2026-6836 · Unknown · 3Dp-Manager
Denpiligrim
·
Published
2026-02-06
·
Updated
2026-02-07
·
CVE-2026-25803
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
3DP-MANAGER versions 2.0.1 and prior
Description
3DP-MANAGER, an inbound generator for 3x-ui, automatically creates an administrative account with default credentials (admin/admin) upon initial setup. An attacker with network access to the application’s login interface can exploit this to gain full administrative control, including the ability to manage VPN tunnels and system settings.
Recommendations
Update to version 2.0.2 to resolve this issue.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
3Dp-Manager