Login credentials are inadvertently recorded in logs if a...
Low severity
Unreviewed
Published
Nov 11, 2025
to the GitHub Advisory Database
•
Updated Dec 8, 2025
Description
Published by the National Vulnerability Database
Nov 11, 2025
Published to the GitHub Advisory Database
Nov 11, 2025
Last updated
Dec 8, 2025
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610
and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6
Access Points). An user having access to the syslog server can read the logs containing these credentials.
This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4.
Devices
managed with Insight get automatic updates. If not, please check the firmware version
and update to the latest.
Fixed in:
WAX610 firmware
11.8.0.10 or later.
WAX610Y firmware
11.8.0.10 or later.
References