CVE-2026-25803Patch(denpiligrim / 3dp-manager)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch denpiligrim 3dp-manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version 2.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 3dp-manager

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-07)
  • 5 total mentions across 2 days

Affected systems

Products
3dp-manager

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-06: 2Mentions · 2026-02-07: 3Patch / Workaround · 2026-02-07: 3Technical Details · 2026-02-06: 2Technical Details · 2026-02-07: 302-0602-07
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-073
Patch3
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Patch

    Denpiligrim 3DP-Manager has a hard-coded credentials vulnerability (CVE-2026-25803). Update to 2.0.1 to address this #security flaw in your #application. More details: https://www.pulsepatch.io/posts/cve-2026-25803-3dp-manager-hardcoded-credentials

    Post summary

    Denpiligrim 3DP‑Manager suffers from a hard‑coded credentials flaw (CVE-2026-25803). Users are advised to upgrade to version 2.0.1 to mitigate the issue.

    0000053
    1 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-25803 in denpiligrim 3dp-manager (≤2.0.1) allows admin takeover via hard-coded creds (admin/admin). Patch ASAP or restrict access! 🔒 https://radar.offseq.com/threat/cve-2026-25803-cwe-798-use-of-hard-coded-credentia-52e7d009 #OffSeq #Vulnerability #Infosec https://t.co/t6KeG5j9Jz

    Post summary

    The tweet alerts that CVE‑2026‑25803 in denpiligrim 3dp‑manager allows admin takeover via hard‑coded credentials and urges users to patch or restrict access.

    0000057
    268 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25803: CRITICAL] Critical security alert! 3DP-MANAGER 2.0.1 & prior creates admin account with default credentials (admin/admin). Attackers can exploit to gain admin control. Update to 2.0.2 ASAP!#cve,CVE-2026-25803,#cybersecurity https://cvefind.com/CVE-2026-25803

    Post summary

    The alert highlights that 3DP‑MANAGER 2.0.1 and earlier versions allow creation of an admin account with default credentials, enabling attackers to gain admin control, and recommends upgrading to version 2.0.2 to remediate the issue.

    0000081
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25803 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credenti… https://www.cve.org/CVERecord?id=CVE-2026-25803

    Post summary

    The post discloses that 3DP-MANAGER version 2.0.1 and earlier auto‑creates an administrative account using default credentials, presenting a credential exposure risk.

    00000201
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25803: 3DP-MANAGER Uses Hard-coded Cred... Hard-coded admin/admin credentials in 3DP-MANAGER <= 2.0.1 give attackers complete control over VPN tunnels with zero r... https://zerodaysignal.com/vulnerability/CVE-2026-25803 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25803, highlighting hard‑coded credentials in 3DP‑MANAGER that grant full VPN control, but offers no PoC, exploit code, or patch information.

    00000105
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdenpiligrim3dp-manager---

Explore more