CVE-2023-27573Disclosure(netboxlabs / netbox-docker)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only about 90% changed the token. Having a default token value was intentional and was valuable for the main intended use case of the netbox-docker product (isolated development networks). Some users engaged in an effort to repurpose netbox-docker for production. The documentation for this effort stated that the defaults must not be used. However, installation did not ensure non-default values. The Supplier was aware of the CVE ID assignment and did not object to the assignment.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1392CWE-798

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netbox-docker

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
netbox-docker

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-11: 2PoC Mentioned / Linked · 2026-03-11: 1Technical Details · 2026-03-11: 203-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2023-27573: netbox-community (CVSS: 9.0)... 90% of netbox-docker users left the hardcoded SUPERUSER_API_TOKEN exposed—pure gold for attackers scanning for 01234567... https://zerodaysignal.com/vulnerability/CVE-2023-27573 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a high‑severity CVE-2023-27573 with an exposed superuser API token and provides a link to additional details, but it does not include exploit code, active exploitation evidence, or patch information.

    0001074
    142 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2023-27573: CRITICAL] Netbox-docker < 2.5.0 has default credentials making it susceptible to cyber threats. While most users changed the password, only 90% altered the token, leaving systems vulnerable.#cve,CVE-2023-27573,#cybersecurity https://cvefind.com/CVE-2023-27573

    Post summary

    The post announces a critical vulnerability in Netbox‑docker (CVE‑2023‑27573) that allows exploitation via default credentials when the token remains unchanged.

    0000044
    601 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnetboxlabsnetbox-docker---

Explore more