An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
History

Thu, 11 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Description An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models. An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
Title Missing TLS certificate validation in ReadyCloud client app Missing TLS certificate validation in NETGEAR's ReadyCloud client app

Wed, 10 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
References

Tue, 09 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear rax120v1
Netgear rax120v2
Netgear rax35
Netgear rax38
Netgear rax40
Vendors & Products Netgear
Netgear rax120v1
Netgear rax120v2
Netgear rax35
Netgear rax38
Netgear rax40

Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models.
Title Missing TLS certificate validation in ReadyCloud client app
Weaknesses CWE-325
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published: 2026-06-09T15:50:53.619Z

Updated: 2026-06-11T05:19:09.117Z

Reserved: 2025-12-03T04:16:27.690Z

Link: CVE-2026-0420

cve-icon Vulnrichment

Updated: 2026-06-09T17:23:12.088Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:00.147

Modified: 2026-06-11T07:16:26.570

Link: CVE-2026-0420

cve-icon Redhat

No data.