5.9

CVE-2026-0420

Missing TLS certificate validation in NETGEAR's ReadyCloud client app

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetgearRax120 Firmware Version < 1.2.9.52
   NetgearRax120 Version-
   NetgearRax120 Version1.0
   NetgearRax120 Version2.0
NetgearRax35 Firmware Version < 1.0.6.106
   NetgearRax35 Version-
NetgearRax38 Firmware Version < 1.0.6.106
   NetgearRax38 Version-
NetgearRax40 Firmware Version < 1.0.6.106
   NetgearRax40 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.033
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NETGEAR 4.6 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

https://www.netgear.com/support/product/rax35/
Product
https://www.netgear.com/support/product/rax38/
Product
https://www.netgear.com/support/product/rax40/
Product
https://www.netgear.com/support/product/rax120v2/
Product
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
Vendor Advisory