NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL.
This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.
This issue has been fixed in version 0.57.0
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netbirdio
Netbirdio netbird |
|
| Vendors & Products |
Netbirdio
Netbirdio netbird |
Mon, 20 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed. This issue has been fixed in version 0.57.0 | |
| Title | Admin with default credentials in NetBird VPN | |
| Weaknesses | CWE-1392 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-10-20T15:41:31.149Z
Updated: 2025-10-20T15:52:13.566Z
Reserved: 2025-09-18T08:50:24.259Z
Link: CVE-2025-10678
Updated: 2025-10-20T15:52:10.344Z
Status : Awaiting Analysis
Published: 2025-10-20T16:15:36.477
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-10678
No data.