CVE-2026-0420

MEDIUM EPSS 3.4%
Published Jun 9, 20262w ago · Modified Jun 18, 20261w ago
4.6 CVSS 4.0
Medium
Find Similar
Published Jun 9, 2026 2w ago
Last Modified Jun 18, 2026 1w ago

Description

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.

CVSS Details

Base Score
4.6
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
3.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-325

Affected Products 10

VendorProductVersionRange
netgearrax120_firmware* <1.2.9.52
netgearrax120*any
netgearrax1201.0any
netgearrax1202.0any
netgearrax35_firmware* <1.0.6.106
netgearrax35*any
netgearrax38_firmware* <1.0.6.106
netgearrax38*any
netgearrax40_firmware* <1.0.6.106
netgearrax40*any

References 5

  • kb.netgear.com https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
    Vendor Advisory
  • netgear.com https://www.netgear.com/support/product/rax120v2/
    Product
  • netgear.com https://www.netgear.com/support/product/rax35/
    Product
  • netgear.com https://www.netgear.com/support/product/rax38/
    Product
  • netgear.com https://www.netgear.com/support/product/rax40/
    Product

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.