Description
An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client app which can allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting product's confidentiality. This vulnerability affects the listed NETGEAR models.
Problem types
CWE-325 Missing cryptographic step
Product status
Any version before V1.2.9.52
Any version before V1.2.9.52
Any version before V1.0.6.106
Any version before V1.0.6.106
Any version before V1.0.6.106
Credits
talsonor
References
www.netgear.com/support/product/rax35/
www.netgear.com/support/product/rax38/
www.netgear.com/support/product/rax40/
www.netgear.com/support/product/rax120v2/
kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory