CVE-2026-27751Disclosure(sodola-network / sl902-swtgw124as)

LOWCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Prioritize remediation for sodola-network sl902-swtgw124as systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to gain full administrative control of the device.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1392

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sl902-swtgw124as
  • sl902-swtgw124as_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
sl902-swtgw124assl902-swtgw124as_firmware

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-27: 4Mentions · 2026-03-01: 1Mentions · 2026-03-04: 1Active Exploitation · 2026-03-01: 1Technical Details · 2026-02-27: 4Technical Details · 2026-03-04: 102-2703-0103-04
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-274
Disclosure4
2026-03-011
Active Exploitation1
2026-03-041
Disclosure1
Full discourse6 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27751: CRITICAL] Warning: SODOLA SL902-SWTGW124AS firmware has a default credentials vulnerability up to version 200.1.20, allowing remote attackers full administrative access without password chan...#cve,CVE-2026-27751,#cybersecurity https://cvefind.com/CVE-2026-27751

    Post summary

    A critical default credentials vulnerability (CVE‑2026‑27751) in SODOLA SL902‑SWTGW124AS firmware allows remote attackers to gain full admin access without a password change.

    1001041
    585 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27751 (CVSS:9.3, CRITICAL) is Analyzed. SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot..https://nvd.nist.gov/vuln/detail/CVE-2026-27751 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27751, a critical default‑credentials flaw in SODOLA firmware (CVSS 9.3), but offers no PoC, exploit, or patch details.

    0000035
    173 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Shenzhen Hongyavision Technology SODOLA SL902-SWTGW124AS (CVE-2026-27751) https://vuldb.com/?ctiid.348202

    Post summary

    The post indicates potential real‑world exploitation activity against the device associated with CVE-2026-27751, but provides no PoC, exploit code, or mitigation details.

    0000075
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27751 Default Credentials Vulnerability in SODOLA SL902-SWTGW124AS Firmware Versions Through 200.1.20 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27751

    Post summary

    A default credentials vulnerability exists in SODOLA SL902‑SWTGW124AS firmware up to version 200.1.20; the brief notice confirms the issue but does not provide a PoC, exploit, or patch.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27751 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to… https://www.cve.org/CVERecord?id=CVE-2026-27751

    Post summary

    The post discloses a default credentials flaw in SODOLA SL902‑SWTGW124AS firmware, enabling remote attackers to gain administrative access.

    00000104
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27751 - Critical SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management inter... https://www.thehackerwire.com/vulnerability/CVE-2026-27751/ https://t.co/uGyuYeoi1P

    Post summary

    The post announces CVE-2026-27751, describing it as a default credential flaw that grants remote administrative access, without mentioning patches, PoC, or active exploitation.

    0000041
    119 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWsodola-networksl902-swtgw124as---
OSsodola-networksl902-swtgw124as_firmware---

Explore more