CVE-2026-0420: Missing TLS certificate validation in NETGEAR's ReadyCloud client app
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RAX120v1to a version that resolves this vulnerability.Fixed in V1.2.9.52 - Upgrade
Upgrade
RAX120v2 (Nighthawk AX12 12-Stream AX6000 WiFi Router)to a version that resolves this vulnerability.Fixed in V1.2.9.52 - Upgrade
Upgrade
RAX35to a version that resolves this vulnerability.Fixed in V1.0.6.106 - Upgrade
Upgrade
RAX38to a version that resolves this vulnerability.Fixed in V1.0.6.106 - Upgrade
Upgrade
RAX40to a version that resolves this vulnerability.Fixed in V1.0.6.106 - Compensating control
Retire devices marked as End-of-Support (EoS) and replace them with newer, supported NETGEAR devices to ensure continued security updates and support.
- Operational
Check each device's firmware version and, if the listed fixed version is not installed, update the device firmware to the fixed version (or to the latest available) via NETGEAR support. Note: devices with automatic updates enabled may already have the patch applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0420?
The severity of CVE-2026-0420 is assessed as medium with a CVSS score of 4.6.
How do I fix CVE-2026-0420?
To fix CVE-2026-0420, ensure your NETGEAR ReadyCloud client app is updated to the latest firmware version.
What is the risk associated with CVE-2026-0420?
CVE-2026-0420 presents a risk of potential attacker-in-the-middle (MiTM) attacks due to missing TLS certificate validation.
Which NETGEAR products are affected by CVE-2026-0420?
CVE-2026-0420 affects various NETGEAR models that utilize the ReadyCloud client app.
When was CVE-2026-0420 published?
CVE-2026-0420 was published on June 9, 2026.