Back to overview

CVE-2026-25803

CRITICAL
9.8
CVSS 3.1
Description
3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.

Metadata

CVE ID
CVE-2026-25803
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-02-05 19:58 UTC
Published
2026-02-06 22:52 UTC
Last updated
2026-02-09 15:25 UTC
Primary CWE
CWE-798
CWE-798: Use of Hard-coded Credentials
Vendor / Product
denpiligrim / 3dp-manager
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
denpiligrim 3dp-manager <= 2.0.1
Weakness (CWE)
CWESourceDescription
CWE-798 cna CWE-798: Use of Hard-coded Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References (2)
Back to overview