Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.
History

Mon, 08 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Netgear wax610 Firmware
Netgear wax610y Firmware
CPEs cpe:2.3:h:netgear:wax610:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wax610y:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wax610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wax610y_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netgear wax610 Firmware
Netgear wax610y Firmware
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Sat, 15 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear wax610
Netgear wax610y
Vendors & Products Netgear
Netgear wax610
Netgear wax610y

Tue, 11 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Description Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.
Title Credentials recorded in logs in NETGEAR WAX610 and WAX610Y
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 0.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published: 2025-11-11T16:17:25.837Z

Updated: 2025-11-14T17:41:18.640Z

Reserved: 2025-11-10T07:33:11.224Z

Link: CVE-2025-12940

cve-icon Vulnrichment

Updated: 2025-11-14T17:41:16.028Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-11T17:15:39.090

Modified: 2025-12-08T14:24:51.363

Link: CVE-2025-12940

cve-icon Redhat

No data.