CVE ID | CVE-2025-10678 |
Publication date | 20 October 2025 |
Vendor | NetBird VPN |
Product | NetBird |
Vulnerable versions | All before 0.57.0 |
Vulnerability type (CWE) | Use of Default Credentials (CWE-1392) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in NetBird VPN software and participated in coordination of its disclosure.
The vulnerability CVE-2025-10678: NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL - default identity provider. This issue affects instances installed using vendor's provided script and may affect instances created with Docker if the default password was not changed or the admin user was not removed.
This issue has been fixed in version 0.57.0
Credits
We thank Adam Sobieraj for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.