← Vulnerability feed

Vulnerability record · CVE-2026-27758 · published 27 February 2026

CVE-2026-27758: Sodola-network sl902-swtgw124as firmware cross-site request forgery vulnerability

Sodola Network · Sl902 Swtgw124as Firmware

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authenticated users into submitting forged requests. Attackers can craft malicious requests that execute unauthorized configuration or administrative actions with the victim's privileges when the authenticated user visits a malicious webpage.

5.1 CVSS 4.0 Medium EPSS 0.16% · top 95.7% CWE-352 · Cross-site request forgery
5.1CVSS 4.0 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authenticated users into submitting forged requests. Attackers can craft malicious requests that execute unauthorized configuration or administrative actions with the victim's privileges when the authenticated user visits a malicious webpage.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27758 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-27755Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge …EPSS 0.73%9.3CVE-2026-27751Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain adminis…EPSS 0.64%8.2CVE-2026-27752Sodola-network sl902-swtgw124as firmware cleartext transmission vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture c…EPSS 0.29%7.1CVE-2026-27757Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account …EPSS 0.47%6.9CVE-2026-27754Sodola-network sl902-swtgw124as firmware vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakenin…EPSS 0.19%6.9CVE-2026-27753Sodola-network sl902-swtgw124as firmware improper restriction of authentication attempts vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unl…EPSS 0.47%5.1CVE-2026-27756Sodola-network sl902-swtgw124as firmware cross-site scripting vulnerabilitySODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where u…EPSS 0.28%9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed

Source: NIST National Vulnerability Database (record CVE-2026-27758), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.