Back to overview

CVE-2026-27751

CRITICAL
9.8
CVSS 3.1
Description
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to gain full administrative control of the device.

Metadata

CVE ID
CVE-2026-27751
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-02-23 21:38 UTC
Published
2026-02-27 18:07 UTC
Last updated
2026-03-02 17:29 UTC
Primary CWE
CWE-1392
CWE-1392 Use of Default Credentials
Vendor / Product
Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks) / SODOLA SL902-SWTGW124AS
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks) SODOLA SL902-SWTGW124AS 0 ≤ 200.1.20
Weakness (CWE)
CWESourceDescription
CWE-1392 cna CWE-1392 Use of Default Credentials
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview