PT-2026-6836 · Unknown · 3Dp-Manager

Denpiligrim

·

Published

2026-02-06

·

Updated

2026-02-07

·

CVE-2026-25803

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 3DP-MANAGER versions 2.0.1 and prior
Description 3DP-MANAGER, an inbound generator for 3x-ui, automatically creates an administrative account with default credentials (admin/admin) upon initial setup. An attacker with network access to the application’s login interface can exploit this to gain full administrative control, including the ability to manage VPN tunnels and system settings.
Recommendations Update to version 2.0.2 to resolve this issue.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-25803
GHSA-5X57-H7CW-9JMW

Affected Products

3Dp-Manager