« Volver al listado

CVE-2025-12940

Estado: AnalizadaBaja (0.5)—

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.

This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4.

Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest.

Fixed in:

WAX610 firmware 11.8.0.10 or later.

WAX610Y firmware 11.8.0.10 or later.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-12940",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-12940",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-11-14T17:41:09.064598Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "USER",
          "baseScore": 0.5,
          "Automatable": "NO",
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "valueDensity": "DIFFUSE",
          "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
          "exploitMaturity": "UNREPORTED",
          "providerUrgency": "AMBER",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "LOW",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
      "affectedData": [
        {
          "vendor": "NETGEAR",
          "product": "WAX610",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "10.8.11.4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "NETGEAR",
          "product": "WAX610Y",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "10.8.11.4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-11-11T17:15:39.090",
  "references": [
    {
      "url": "https://kb.netgear.com/000070355/NETGEAR-Security-Advisories-November-2025",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/wax610",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://www.netgear.com/support/product/wax610y",
      "tags": [
        "Product"
      ],
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610\nand WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6\nAccess Points). An user having access to the syslog server can read the logs containing these credentials. \n\nThis issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4.\n\n\nDevices\nmanaged with Insight get automatic updates. If not, please check the firmware version\nand update to the latest. \n\n\n\n\n\nFixed in:\n\n\n\nWAX610 firmware\n11.8.0.10 or later.\n\n\n\nWAX610Y firmware\n11.8.0.10 or later."
    }
  ],
  "lastModified": "2026-06-17T08:33:15.293",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wax610y_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1103F99-4FFD-4B3E-A461-48FF194CCD0F",
              "versionEndExcluding": "11.8.0.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wax610y:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "724E738E-FB14-4190-94F4-B0442248BD1E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wax610_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C286EAF-C6D2-4132-8FCF-79937B12C289",
              "versionEndExcluding": "11.8.0.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wax610:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5C86845A-17B3-40B4-AAFD-E703FDB8A1EE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}