Vulnerability Description
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Rax120 Firmware | < 1.2.9.52 |
| Netgear | Rax120 | - |
| Netgear | Rax35 Firmware | < 1.0.6.106 |
| Netgear | Rax35 | - |
| Netgear | Rax38 Firmware | < 1.0.6.106 |
| Netgear | Rax38 | - |
| Netgear | Rax40 Firmware | < 1.0.6.106 |
| Netgear | Rax40 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-AdvisoryVendor Advisory
- https://www.netgear.com/support/product/rax120v2/Product
- https://www.netgear.com/support/product/rax35/Product
- https://www.netgear.com/support/product/rax38/Product
- https://www.netgear.com/support/product/rax40/Product
FAQ
What is CVE-2026-0420?
CVE-2026-0420 is a vulnerability with a CVSS score of 5.9 (MEDIUM). An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks imp...
How severe is CVE-2026-0420?
CVE-2026-0420 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-0420?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Rax120 Firmware, Netgear Rax120, Netgear Rax35 Firmware, Netgear Rax35, Netgear Rax38 Firmware.