Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.
History

Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear wax610
Netgear wax610y
Vendors & Products Netgear
Netgear wax610
Netgear wax610y

Tue, 11 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Description Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.
Title Credentials recorded in logs in NETGEAR WAX610 and WAX610Y
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 0.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published: 2025-11-11T16:17:25.837Z

Updated: 2025-11-11T16:17:25.837Z

Reserved: 2025-11-10T07:33:11.224Z

Link: CVE-2025-12940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-11T17:15:39.090

Modified: 2025-11-11T17:15:39.090

Link: CVE-2025-12940

cve-icon Redhat

No data.