An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
References
| Link | Resource |
|---|---|
| https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory | Vendor Advisory |
| https://www.netgear.com/support/product/rax120v2/ | Product |
| https://www.netgear.com/support/product/rax35/ | Product |
| https://www.netgear.com/support/product/rax38/ | Product |
| https://www.netgear.com/support/product/rax40/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
No history.
Information
Published : 2026-06-09 17:17
Updated : 2026-07-23 08:10
NVD link : CVE-2026-0420
Mitre link : CVE-2026-0420
CVE.ORG link : CVE-2026-0420
JSON object : View
Products Affected
netgear
- rax120
- rax120_firmware
- rax40
- rax38
- rax35_firmware
- rax38_firmware
- rax35
- rax40_firmware
CWE
CWE-325
Missing Cryptographic Step
