NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL.
This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.
This issue has been fixed in version 0.57.0
This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.
This issue has been fixed in version 0.57.0
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
GHSA-g3j4-58mp-3x25 | NetBird VPN does not remove the default password of an admin account |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 20 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 20 Oct 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed. This issue has been fixed in version 0.57.0 | |
Title | Admin with default credentials in NetBird VPN | |
Weaknesses | CWE-1392 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-10-20T15:52:13.566Z
Reserved: 2025-09-18T08:50:24.259Z
Link: CVE-2025-10678

Updated: 2025-10-20T15:52:10.344Z

Status : Received
Published: 2025-10-20T16:15:36.477
Modified: 2025-10-20T16:15:36.477
Link: CVE-2025-10678

No data.

No data.