Back to overview

CVE-2026-27755

CRITICAL
9.8
CVSS 3.1
Description
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the session identifier offline and bypass authentication without completing the login flow, gaining unauthorized access to the device.

Metadata

CVE ID
CVE-2026-27755
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-02-23 21:38 UTC
Published
2026-02-27 18:09 UTC
Last updated
2026-03-02 17:30 UTC
Primary CWE
CWE-330
CWE-330 Use of Insufficiently Random Values
Vendor / Product
Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks) / SODOLA SL902-SWTGW124AS
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks) SODOLA SL902-SWTGW124AS 0 ≤ 200.1.20
Weakness (CWE)
CWESourceDescription
CWE-330 cna CWE-330 Use of Insufficiently Random Values
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview