« Volver al listado

Sodola-network

Sodola-network Sl902-swtgw124as Firmware: vulnerabilidades y CVE

Sodola-network Sl902-swtgw124as Firmware tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses8
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-27758Media (5.1)0.16%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authenticated users into submitting forged…
CVE-2026-27757Alta (7.1)0.47%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain…
CVE-2026-27756Media (5.1)0.28%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft…
CVE-2026-27755Crítica (9.3)0.73%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies.…
CVE-2026-27754Media (6.9)0.19%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakening session security. Attackers can exploit predictable session tokens…
CVE-2026-27753Media (6.9)0.47%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can…
CVE-2026-27752Alta (8.2)0.29%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between…
CVE-2026-27751Crítica (9.3)0.64%—27 feb 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078.001 Default Accounts2
  2. T1190 Exploit Public-Facing Application2
  3. T1210 Exploitation of Remote Services1
  4. T1212 Exploitation for Credential Access1
  5. T1557 Adversary-in-the-Middle1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.