GHSA-g3j4-58mp-3x25 · Severity: critical · Ecosystem: go — NetBird VPN does not remove the default password of an admin account
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed. This issue has been fixed in version 0.57.0
Conclusion & alert: CVE-2025-10678 is rated Moderate Risk (47.6/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.38%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-17 | 0.35% | 0.38% | +0.03% |
| 2 | 2026-06-15 | 0.05% | 0.35% | +0.29% |
| 3 | 2025-10-26 | — | 0.05% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | [email protected] |
GHSA-g3j4-58mp-3x25 · Severity: critical · Ecosystem: go — NetBird VPN does not remove the default password of an admin account
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||