CVE-2025-55740

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files config.yaml and docker-compose.yml contain default credentials (default_password: "change_me_please", GF_SECURITY_ADMIN_PASSWORD=admin123). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections. The issue is addressed in v1.5.0 and later.
Configurations

No configuration.

History

No history.

Information

Published : 2025-08-19 20:15

Updated : 2025-08-20 14:40


NVD link : CVE-2025-55740

Mitre link : CVE-2025-55740

CVE.ORG link : CVE-2025-55740


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials