ID

VAR-202606-2971


CVE

CVE-2026-0420


TITLE

of netgear RAX120  Vulnerabilities related to flaws in encryption processing across multiple products, including firmware.

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453

DESCRIPTION

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models. This vulnerability allows an attacker to carry out a man-in-the-middle attack that could affect the confidentiality of the product. MiTM This vulnerability may allow the execution of the following actions. NETGEAR This will affect the model.- All information handled by the software may be leaked to external parties. - No rewriting will occur to the information handled by the software. - The software will not stop

Trust: 1.62

sources: NVD: CVE-2026-0420 // JVNDB: JVNDB-2026-020453

AFFECTED PRODUCTS

vendor:netgearmodel:rax35scope:ltversion:1.0.6.106

Trust: 1.0

vendor:netgearmodel:rax120scope:ltversion:1.2.9.52

Trust: 1.0

vendor:netgearmodel:rax38scope:ltversion:1.0.6.106

Trust: 1.0

vendor:netgearmodel:rax40scope:ltversion:1.0.6.106

Trust: 1.0

vendor:ネットギアmodel:rax120scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rax38scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rax40scope: - version: -

Trust: 0.8

vendor:ネットギアmodel:rax35scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453 // NVD: CVE-2026-0420

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2026-0420
value: MEDIUM

Trust: 1.0

a2826606-91e7-4eb6-899e-8484bd4575d5: CVE-2026-0420
value: MEDIUM

Trust: 1.0

NVD: CVE-2026-0420
value: MEDIUM

Trust: 0.8

nvd@nist.gov: CVE-2026-0420
baseSeverity: MEDIUM
baseScore: 5.9
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2026-0420
baseSeverity: MEDIUM
baseScore: 5.9
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453 // NVD: CVE-2026-0420 // NVD: CVE-2026-0420

PROBLEMTYPE DATA

problemtype:CWE-325

Trust: 1.0

problemtype:Inadequate encryption processing (CWE-325) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453 // NVD: CVE-2026-0420

PATCH

title:June 2026 NETGEAR Security Advisory - NETGEAR Supporturl:https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453

EXTERNAL IDS

db:NVDid:CVE-2026-0420

Trust: 2.6

db:JVNDBid:JVNDB-2026-020453

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453 // NVD: CVE-2026-0420

REFERENCES

url:https://www.netgear.com/support/product/rax35/

Trust: 1.8

url:https://www.netgear.com/support/product/rax38/

Trust: 1.8

url:https://www.netgear.com/support/product/rax40/

Trust: 1.8

url:https://www.netgear.com/support/product/rax120v2/

Trust: 1.8

url:https://kb.netgear.com/000070811/june-2026-netgear-security-advisory

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-0420

Trust: 0.8

sources: JVNDB: JVNDB-2026-020453 // NVD: CVE-2026-0420

SOURCES

db:JVNDBid:JVNDB-2026-020453
db:NVDid:CVE-2026-0420

LAST UPDATE DATE

2026-07-24T23:10:10.718000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-020453date:2026-06-22T02:44:00
db:NVDid:CVE-2026-0420date:2026-07-23T08:10:00.137

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-020453date:2026-06-22T00:00:00
db:NVDid:CVE-2026-0420date:2026-06-09T17:17:00.147