CVE-2026-0420

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:rax120_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:netgear:rax120:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax120:1.0:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax120:2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:rax35_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax35:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:rax38_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax38:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rax40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax40:-:*:*:*:*:*:*:*

History

18 Jun 2026, 17:08

Type Values Removed Values Added
CPE cpe:2.3:o:netgear:rax40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax35:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax38:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax120:2.0:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax38_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax35_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax40:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax120:1.0:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax120:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
First Time Netgear rax40 Firmware
Netgear rax35
Netgear rax120
Netgear rax38 Firmware
Netgear rax38
Netgear rax40
Netgear rax35 Firmware
Netgear
Netgear rax120 Firmware
References () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory - () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory - Vendor Advisory
References () https://www.netgear.com/support/product/rax120v2/ - () https://www.netgear.com/support/product/rax120v2/ - Product
References () https://www.netgear.com/support/product/rax35/ - () https://www.netgear.com/support/product/rax35/ - Product
References () https://www.netgear.com/support/product/rax38/ - () https://www.netgear.com/support/product/rax38/ - Product
References () https://www.netgear.com/support/product/rax40/ - () https://www.netgear.com/support/product/rax40/ - Product

11 Jun 2026, 07:16

Type Values Removed Values Added
Summary (en) An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models. (en) An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.

10 Jun 2026, 14:16

Type Values Removed Values Added
References
  • () https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory -

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-06-18 17:08


NVD link : CVE-2026-0420

Mitre link : CVE-2026-0420

CVE.ORG link : CVE-2026-0420


JSON object : View

Products Affected

netgear

  • rax120_firmware
  • rax40
  • rax40_firmware
  • rax38_firmware
  • rax38
  • rax35_firmware
  • rax120
  • rax35
CWE
CWE-325

Missing Cryptographic Step