5.9
CVE-2026-0420
- EPSS 0.14%
- Veröffentlicht 09.06.2026 15:50:53
- Zuletzt bearbeitet 23.07.2026 08:10:00
- CVE-Watchlists
- Unerledigt
Missing TLS certificate validation in NETGEAR's ReadyCloud client app
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Rax120 Firmware Version < 1.2.9.52
Netgear ≫ Rax35 Firmware Version < 1.0.6.106
Netgear ≫ Rax38 Firmware Version < 1.0.6.106
Netgear ≫ Rax40 Firmware Version < 1.0.6.106
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.033 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NETGEAR | 4.6 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-325 Missing Cryptographic Step
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
https://www.netgear.com/support/product/rax35/
https://www.netgear.com/support/product/rax38/
https://www.netgear.com/support/product/rax40/
https://www.netgear.com/support/product/rax120v2/
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory