An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models.

Project Subscriptions

Vendors Products
Netgear Subscribe
Advisories

No advisories yet.

Fixes

Solution

NETGEAR strongly recommends that you install the latest firmware as soon as possible. Issue fixed in: ProductFixed VersionRAX120v1*V1.2.9.52RAX120v2 V1.2.9.52 https://www.netgear.com/support/product/rax120v2/ RAX35* V1.0.6.106 https://www.netgear.com/support/product/rax35/ RAX38* V1.0.6.106 https://www.netgear.com/support/product/rax38/ RAX40* V1.0.6.106 https://www.netgear.com/support/product/rax40/ * Model has reached its End-of-Support phase and no future security updates are planned. NETGEAR strongly recommends that you retire this device and upgrade to a newer NETGEAR product for continued security support.


Workaround

No workaround given by the vendor.

History

Tue, 09 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rax120v1
Netgear rax120v2
Netgear rax35
Netgear rax38
Netgear rax40
Vendors & Products Netgear
Netgear rax120v1
Netgear rax120v2
Netgear rax35
Netgear rax38
Netgear rax40

Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models.
Title Missing TLS certificate validation in ReadyCloud client app
Weaknesses CWE-325
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-06-09T17:23:31.036Z

Reserved: 2025-12-03T04:16:27.690Z

Link: CVE-2026-0420

cve-icon Vulnrichment

Updated: 2026-06-09T17:23:12.088Z

cve-icon NVD

Status : Received

Published: 2026-06-09T17:17:00.147

Modified: 2026-06-09T17:17:00.147

Link: CVE-2026-0420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T17:30:10Z

Weaknesses