CVE-2025-10221: Hardcoded Password Exposure in AxxonNet (C-WerkNet) ARP Agent Logs
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Axxon One (C-Werk)to a version that resolves this vulnerability.Fixed in 3.15.0 - Configuration
Do not enable TRACE logging in production environments.
Axxon One / AxxonNet / C-WerkNet ARP Agent TRACE logging = disabled in production - Operational
Rotate credentials if TRACE logging had previously been enabled.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10221?
CVE-2025-10221 has been classified as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-10221?
To fix CVE-2025-10221, upgrade to AxxonSoft Axxon One / AxxonNet version 2.0.5 or later.
Who is affected by CVE-2025-10221?
CVE-2025-10221 affects users of AxxonSoft Axxon One / AxxonNet versions 2.0.4 and earlier on Windows platforms.
What kind of information is exposed by CVE-2025-10221?
CVE-2025-10221 exposes plaintext credentials stored in TRACE log files, which may include serialized JSON with passwords.
Can a remote attacker exploit CVE-2025-10221?
No, CVE-2025-10221 requires local access to exploit the vulnerability, as it involves reading log files.