LOW RISK
CVE-2025-12940
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials. …
SMB Attack Probability Score
13/100low
Weighted: EPSS · CISA KEV · SMB stack prevalence · exploit maturity · CVSS vector
CVSS v3
5.5
EPSS (30d)
0.04%
SMB Exposure
57.6/100
Attack Vector
LOCAL
Complexity
LOW
Privileges
LOW
Affected Products
wax610y firmwarewax610 firmwarewax610wax610y
Remediation & References
What to do
💻Local access required — review endpoint hardeninglow
An attacker needs local access to exploit this. Focus on endpoint detection, privilege management, and preventing initial compromise (phishing, malicious USB).
NVD Full Entry ↗Official vulnerability detail, CVSS vectors, CPE listEPSS Score ↗Exploit Prediction Scoring System — FIRST.orgMitre CVE ↗MITRE CVE Program official entry
Vendor & Exploit References
Scoring Methodology
SMB Attack Probability Score weights: EPSS exploit likelihood (35%), CISA KEV active exploitation (25%), SMB stack prevalence (20%), exploit maturity (10%), CVSS network vector complexity (10%). Impact scenarios are derived from software category and historical SMB incident patterns. Scores recompute daily.