CVE-2025-55740

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files config.yaml and docker-compose.yml contain default credentials (default_password: "change_me_please", GF_SECURITY_ADMIN_PASSWORD=admin123). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections. The issue is addressed in v1.5.0 and later.
CVSS

No CVSS.

Configurations

No configuration.

History

19 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 20:15

Updated : 2025-08-19 20:15


NVD link : CVE-2025-55740

Mitre link : CVE-2025-55740


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials