Sodola-network
Sodola-network Sl902-swtgw124as Firmware: vulnerabilidades y CVE
Sodola-network Sl902-swtgw124as Firmware tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses8
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27758 | Media (5.1) | 0.16% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authenticated users into submitting forged… |
| CVE-2026-27757 | Alta (7.1) | 0.47% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain… |
| CVE-2026-27756 | Media (5.1) | 0.28% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft… |
| CVE-2026-27755 | Crítica (9.3) | 0.73% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies.… |
| CVE-2026-27754 | Media (6.9) | 0.19% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakening session security. Attackers can exploit predictable session tokens… |
| CVE-2026-27753 | Media (6.9) | 0.47% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can… |
| CVE-2026-27752 | Alta (8.2) | 0.29% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between… |
| CVE-2026-27751 | Crítica (9.3) | 0.64% | — | 27 feb 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.