CVE-2025-12940 - CVE House
Back to Database
Status published Low CVE-2025-12940

Credentials recorded in logs in NETGEAR WAX610 and WAX610Y

Vulnerability Description

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12940

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • filiperfonseca

Affected Vendor

Affected Software

WAX610, WAX610Y
Vulnerable Versions:
0

Timeline

Official Publish: November 11th, 2025
Last Modified: November 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)