CVE-2026-27752
SODOLA SL902-SWTGW124AS <= 200.1.20 Cleartext Credential Transmission
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administrative access to the gateway.
| CWE | CWE-319 |
| Vendor | shenzhen hongyavision technology co., ltd. (sodola networks) |
| Product | sodola sl902-swtgw124as |
| Published | Feb 27, 2026 |
| Last Updated | Mar 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for shenzhen hongyavision technology co., ltd. (sodola networks) sodola sl902-swtgw124as
Be the first to know when new medium vulnerabilities affecting shenzhen hongyavision technology co., ltd. (sodola networks) sodola sl902-swtgw124as are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks) / SODOLA SL902-SWTGW124AS
0 โค 200.1.20
References
sodola-network.com: https://www.sodola-network.com/products/sodola-6-port-2-5g-easy-web-managed-switch-4-x-2-5g-base-t-ports-2-x-10g-sfp-static-aggregation-qos-vlan-igmp-2-5gb-network-home-lab-switch vulncheck.com: https://www.vulncheck.com/advisories/sodola-sl902-swtgw124as-cleartext-credential-transmission
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.