CVE-2026-27757 Details
Description
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to maintain persistent access to the management interface.
An authentication vulnerability has been identified in SODOLA SL902-SWTGW124AS firmware versions through 200.1.20. This vulnerability allows authenticated users to change account passwords without verifying the current password. As a result, attackers who gain access to an authenticated session can modify credentials, ensuring persistent access to the management interface.
Users can upgrade to the latest firmware version, which is available on the SODOLA website. Instructions for upgrading the firmware are included in the SODOLA Managed Switch Web Manual.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-620 | Unverified Password Change | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sodola-network sl902-swtgw124as firmware | <= 200.1.20 |
CPE
Remediation
| |
| sodola-network sl902-swtgw124as | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |