← Vulnerability feed

Vulnerability record · CVE-2026-27753 · published 27 February 2026

CVE-2026-27753: Sodola-network sl902-swtgw124as firmware improper restriction of authentication attempts vulnerability

Sodola Network · Sl902 Swtgw124as Firmware

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can conduct online password guessing attacks without account lockout or rate limiting restrictions to gain unauthorized access to the device management interface.

6.9 CVSS 4.0 Medium EPSS 0.47% · top 61.5% CWE-307 · Improper restriction of authentication attempts
6.9CVSS 4.0 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against the management interface. Attackers can conduct online password guessing attacks without account lockout or rate limiting restrictions to gain unauthorized access to the device management interface.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27753 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-27755Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge …EPSS 0.73%9.3CVE-2026-27751Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain adminis…EPSS 0.64%8.2CVE-2026-27752Sodola-network sl902-swtgw124as firmware cleartext transmission vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture c…EPSS 0.29%7.1CVE-2026-27757Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account …EPSS 0.47%6.9CVE-2026-27754Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakenin…EPSS 0.19%5.1CVE-2026-27758Sodola-network sl902-swtgw124as firmware cross-site request forgery vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows…EPSS 0.16%5.1CVE-2026-27756Sodola-network sl902-swtgw124as firmware cross-site scripting vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where u…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2026-27753), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.