3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.
History

Mon, 09 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Denpiligrim
Denpiligrim 3dp-manager
Vendors & Products Denpiligrim
Denpiligrim 3dp-manager

Fri, 06 Feb 2026 23:00:00 +0000

Type Values Removed Values Added
Description 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.
Title 3DP-MANAGER Uses Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-06T22:52:40.631Z

Updated: 2026-02-09T15:25:57.618Z

Reserved: 2026-02-05T19:58:01.641Z

Link: CVE-2026-25803

cve-icon Vulnrichment

Updated: 2026-02-09T15:22:49.200Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-06T23:15:54.973

Modified: 2026-02-09T16:08:55.263

Link: CVE-2026-25803

cve-icon Redhat

No data.