SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to maintain persistent access to the management interface.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to maintain persistent access to the management interface. | |
| Title | SODOLA SL902-SWTGW124AS <= 200.1.20 Unverified Password Change | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-27T18:58:26.451Z
Reserved: 2026-02-23T21:38:48.842Z
Link: CVE-2026-27757
Updated: 2026-02-27T18:58:21.834Z
Status : Received
Published: 2026-02-27T19:16:09.990
Modified: 2026-02-27T19:16:09.990
Link: CVE-2026-27757
No data.
OpenCVE Enrichment
No data.