CVE-2025-55740
published 2025-08-19CVE-2025-55740: nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.22%
12.9th percentile
nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files
config.yaml and docker-compose.yml contain default credentials (default_password: "change_me_please", GF_SECURITY_ADMIN_PASSWORD=admin123). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections. The issue is addressed in v1.5.0 and later.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| anipaleja | nginx-defender | < 1.5.0 | 1.5.0 |
| github.com | anipaleja_nginx-defender | >= 0 < 1.5.0 | 1.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Default Credentials in nginx-defender Configuration Files in github.com/Anipaleja/nginx-defender
osv·2025-08-29
CVE-2025-55740 Default Credentials in nginx-defender Configuration Files in github.com/Anipaleja/nginx-defender
Default Credentials in nginx-defender Configuration Files in github.com/Anipaleja/nginx-defender
Default Credentials in nginx-defender Configuration Files in github.com/Anipaleja/nginx-defender
OSV
Default Credentials in nginx-defender Configuration Files
osv·2025-08-19
CVE-2025-55740 [MEDIUM] Default Credentials in nginx-defender Configuration Files
Default Credentials in nginx-defender Configuration Files
### Impact
This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files
[config.yaml](https://github.com/Anipaleja/nginx-defender/blob/main/config.yaml), [docker-compose.yml](https://github.com/Anipaleja/nginx-defender/blob/main/docker-compose.yml) contain default credentials (`default_password: "change_me_please"`, `GF_SECURITY_ADMIN_PASSWORD=admin123`). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections.
**Who is impacted?**
All users who deploy nginx-defender with default credentials and expose the admin interface to untrusted networks.
### Patches
The issue is addressed in v1.
GHSA
Default Credentials in nginx-defender Configuration Files
ghsa·2025-08-19
CVE-2025-55740 [MEDIUM] CWE-1392 Default Credentials in nginx-defender Configuration Files
Default Credentials in nginx-defender Configuration Files
### Impact
This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files
[config.yaml](https://github.com/Anipaleja/nginx-defender/blob/main/config.yaml), [docker-compose.yml](https://github.com/Anipaleja/nginx-defender/blob/main/docker-compose.yml) contain default credentials (`default_password: "change_me_please"`, `GF_SECURITY_ADMIN_PASSWORD=admin123`). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections.
**Who is impacted?**
All users who deploy nginx-defender with default credentials and expose the admin interface to untrusted networks.
### Patches
The issue is addressed in v1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-19
Published