Description
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610
and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6
Access Points). An user having access to the syslog server can read the logs containing these credentials. 

This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4.


Devices
managed with Insight get automatic updates. If not, please check the firmware version
and update to the latest.





Fixed in:



WAX610 firmware
11.8.0.10 or later.



WAX610Y firmware
11.8.0.10 or later.
Published: 2025-11-11
Score: 0.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Netgear wax610 Firmware
Netgear wax610y Firmware
CPEs cpe:2.3:h:netgear:wax610:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wax610y:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wax610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wax610y_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netgear wax610 Firmware
Netgear wax610y Firmware
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Sat, 15 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear wax610
Netgear wax610y
Vendors & Products Netgear
Netgear wax610
Netgear wax610y

Tue, 11 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Description Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.
Title Credentials recorded in logs in NETGEAR WAX610 and WAX610Y
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 0.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Amber'}


Subscriptions

Netgear Wax610 Wax610 Firmware Wax610y Wax610y Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2025-11-14T17:41:18.640Z

Reserved: 2025-11-10T07:33:11.224Z

Link: CVE-2025-12940

cve-icon Vulnrichment

Updated: 2025-11-14T17:41:16.028Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-11T17:15:39.090

Modified: 2025-12-08T14:24:51.363

Link: CVE-2025-12940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-12T12:40:13Z

Weaknesses