3DP-Manager Hard-Coded Credentials Vulnerability in Administrative Account Creation

Vulnerability

A vulnerability exists in 3DP-Manager versions through 2.0.1, where the application automatically generates an administrative account with default credentials (admin/admin) during initial setup. This issue allows attackers with network access to the login interface to gain full administrative rights, including management of VPN tunnels and system settings.

Impact

Exploitation of this vulnerability allows for unauthorized administrative access, enabling full control over the application's settings and VPN management.

Reproduction

The vulnerability can be reproduced by deploying 3DP-Manager version 2.0.1 or earlier. Upon the first initialization, the application will create an admin account with the username 'admin' and password 'admin'. This default account can then be used to log in and gain administrative privileges.

Remediation

Users are advised to update to 3DP-Manager version 2.0.2 or later. After updating, if the admin account was created in an earlier version, the password should be changed via the settings UI.

Added: Feb 6, 2026, 11:23 PM
Updated: Feb 6, 2026, 11:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.4
remediation
0.0
relevance
2.6
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.