SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visited by authenticated users.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sodola-network
Sodola-network sl902-swtgw124as Sodola-network sl902-swtgw124as Firmware |
|
| CPEs | cpe:2.3:h:sodola-network:sl902-swtgw124as:-:*:*:*:*:*:*:* cpe:2.3:o:sodola-network:sl902-swtgw124as_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sodola-network
Sodola-network sl902-swtgw124as Sodola-network sl902-swtgw124as Firmware |
Mon, 02 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sodolanetworks
Sodolanetworks sodola Sl902-swtgw124as Firmware |
|
| CPEs | cpe:2.3:o:sodolanetworks:sodola_sl902-swtgw124as_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sodolanetworks
Sodolanetworks sodola Sl902-swtgw124as Firmware |
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shenzhen Hongyavision Technology Co
Shenzhen Hongyavision Technology Co sodola Sl902-swtgw124as |
|
| Vendors & Products |
Shenzhen Hongyavision Technology Co
Shenzhen Hongyavision Technology Co sodola Sl902-swtgw124as |
Fri, 27 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visited by authenticated users. | |
| Title | SODOLA SL902-SWTGW124AS <= 200.1.20 Reflected XSS in Management Interface | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-27T18:10:26.530Z
Updated: 2026-03-02T17:30:06.047Z
Reserved: 2026-02-23T21:38:48.842Z
Link: CVE-2026-27756
Updated: 2026-02-27T18:59:16.426Z
Status : Analyzed
Published: 2026-02-27T19:16:09.763
Modified: 2026-03-03T19:12:22.217
Link: CVE-2026-27756
No data.
ReportizFlow