3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Denpiligrim
Denpiligrim 3dp-manager |
|
| Vendors & Products |
Denpiligrim
Denpiligrim 3dp-manager |
Fri, 06 Feb 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2. | |
| Title | 3DP-MANAGER Uses Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-06T22:52:40.631Z
Updated: 2026-02-09T15:25:57.618Z
Reserved: 2026-02-05T19:58:01.641Z
Link: CVE-2026-25803
Updated: 2026-02-09T15:22:49.200Z
Status : Awaiting Analysis
Published: 2026-02-06T23:15:54.973
Modified: 2026-02-09T16:08:55.263
Link: CVE-2026-25803
No data.