nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files
config.yaml and docker-compose.yml contain default credentials (default_password: "change_me_please", GF_SECURITY_ADMIN_PASSWORD=admin123). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections. The issue is addressed in v1.5.0 and later.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 Aug 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-19 20:15
Updated : 2025-08-19 20:15
NVD link : CVE-2025-55740
Mitre link : CVE-2025-55740
JSON object : View
Products Affected
No product.
CWE
CWE-1392
Use of Default Credentials