5.9

CVE-2026-0420

Missing TLS certificate validation in NETGEAR's ReadyCloud client app

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Rax120 Firmware Version < 1.2.9.52
   Netgear ≫ Rax120 Version -
   Netgear ≫ Rax120 Version 1.0
   Netgear ≫ Rax120 Version 2.0
Netgear ≫ Rax35 Firmware Version < 1.0.6.106
   Netgear ≫ Rax35 Version -
Netgear ≫ Rax38 Firmware Version < 1.0.6.106
   Netgear ≫ Rax38 Version -
Netgear ≫ Rax40 Firmware Version < 1.0.6.106
   Netgear ≫ Rax40 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.033
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NETGEAR 4.6 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

https://www.netgear.com/support/product/rax35/
Product
https://www.netgear.com/support/product/rax38/
Product
https://www.netgear.com/support/product/rax40/
Product
https://www.netgear.com/support/product/rax120v2/
Product
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
Vendor Advisory