CVE-2026-27752: Sodola-Network SL902-SWTGW124AS Firmware

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administrative access to the gateway.

Affected products

  • Sodola-Network SL902-SWTGW124AS Firmware: up to and including 200.1.20

Published 2026-02-27. Last modified 2026-06-17.