SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visited by authenticated users.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visited by authenticated users. | |
| Title | SODOLA SL902-SWTGW124AS <= 200.1.20 Reflected XSS in Management Interface | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-27T18:59:21.071Z
Reserved: 2026-02-23T21:38:48.842Z
Link: CVE-2026-27756
Updated: 2026-02-27T18:59:16.426Z
Status : Received
Published: 2026-02-27T19:16:09.763
Modified: 2026-02-27T19:16:09.763
Link: CVE-2026-27756
No data.
OpenCVE Enrichment
No data.