Junglewise Threat Intelligence

CVE-2026-0420: NETGEAR ReadyCloud improper TLS certificate validation

CVE-2026-0420 · Severity: info · CVSS 4.6 · Published 2026-06-09

Vendors: NETGEAR.

Executive brief

A security flaw in the NETGEAR ReadyCloud client application fails to properly verify digital certificates during encrypted communications. This allows a sophisticated attacker to intercept and read private data transmitted between the user and their storage device. Such an attack could lead to the exposure of sensitive files or login credentials if the attacker is positioned on the same network path.

Technical details

The NETGEAR ReadyCloud client application suffers from an improper implementation of TLS certificate validation (CWE-325). This flaw allows a network-positioned attacker to intercept traffic by presenting a forged certificate that the application fails to reject. While the attack requires the adversary to be in a position to intercept network traffic (Man-in-the-Middle), a successful exploit enables the decryption of communications between the client and the affected NETGEAR router models (RAX120v2, RAX35, RAX38, and RAX40). This impacts the confidentiality of the data transmitted through the ReadyCloud service.

Affected products

  • NETGEAR ReadyCloud client app RAX120v2, RAX35, RAX38, RAX40

Timeline

  • 2026-06-09: disclosed: Initial publication of CVE-2026-0420

References