CVE-2025-10678
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
20/10/2025
Last modified:
21/10/2025
Description
NetBird VPN when installed using vendor&#39;s provided script failed to remove or change default password of an admin account created by ZITADEL.<br />
This issue affects instances installed using vendor&#39;s provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.<br />
<br />
This issue has been fixed in version 0.57.0
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



