CVE-2026-25803

Source
https://cve.org/CVERecord?id=CVE-2026-25803
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25803.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25803
Aliases
  • GHSA-5x57-h7cw-9jmw
Published
2026-02-06T22:52:40.631Z
Modified
2026-02-08T04:08:29.133350Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
3DP-MANAGER Uses Hard-coded Credentials
Details

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.

Database specific
{
    "cwe_ids": [
        "CWE-798"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25803.json"
}
References

Affected packages

Git / github.com/denpiligrim/3dp-manager

Affected ranges

Type
GIT
Repo
https://github.com/denpiligrim/3dp-manager
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0
v1.0.1
v1.0.2
v2.*
v2.0.0
v2.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25803.json"