# CVE-2026-0420

## Summary

- **CVE ID:** CVE-2026-0420
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U)
- **CWE:** CWE-325
- **Published:** Jun 9, 2026
- **Last Modified:** Jun 11, 2026

## Description

An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models.

## Affected Products

- NETGEAR — RAX120v1 (0)
- NETGEAR — RAX120v2 (0)
- NETGEAR — RAX35 (0)
- NETGEAR — RAX38 (0)
- NETGEAR — RAX40 (0)

## References

- [CNA](https://www.netgear.com/support/product/rax35/)
- [CNA](https://www.netgear.com/support/product/rax38/)
- [CNA](https://www.netgear.com/support/product/rax40/)
- [CNA](https://www.netgear.com/support/product/rax120v2/)
- [CNA](https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._