CVE Feed

    Dashboard / CVE / CVE-2023-27573

    CVE-2023-27573

    netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only about 90% changed the token. Having a default token value was intentional and was valuable for the main intended use case of the netbox-docker product (isolated development networks). Some users engaged in an effort to repurpose netbox-docker for production. The documentation for this effort stated that the defaults must not be used. However, installation did not ensure non-default values. The Supplier was aware of the CVE ID assignment and did not object to the assignment.

    Published:Mar 11, 2026
    Last Modified:May 7, 2026
    EPS:Mar 11, 2026
    EPSS Score:0.00056
    CVSS Score:9

    Affected Products

    Vendor
    Netbox
    Product
    Netbox-docker
    Vendor
    Netboxlabs
    Product
    Netbox-docker

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High