CVE-2026-27755Disclosure(sodola-network / sl902-swtgw124as)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the session identifier offline and bypass authentication without completing the login flow, gaining unauthorized access to the device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-330

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sl902-swtgw124as
  • sl902-swtgw124as_firmware

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
sl902-swtgw124assl902-swtgw124as_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-27: 3Mentions · 2026-03-04: 1Technical Details · 2026-02-27: 3Technical Details · 2026-03-04: 102-2703-04
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-273
Disclosure3
2026-03-041
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27755 (CVSS:9.3, CRITICAL) is Analyzed. SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability th..https://nvd.nist.gov/vuln/detail/CVE-2026-27755 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27755, a critical weak session identifier generation flaw in SODOLA firmware (CVSS 9.3), but provides no PoC, exploit, or patch details.

    0000035
    173 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27755: CRITICAL] Vulnerability in SODOLA SL902-SWTGW124AS firmware v200.1.20 allows attackers to forge authenticated sessions via weak session identifier generation, gaining unauthorized access.#cve,CVE-2026-27755,#cybersecurity https://cvefind.com/CVE-2026-27755

    Post summary

    A critical session identifier weakness in SODOLA SL902 firmware allows attackers to forge authenticated sessions and gain unauthorized access.

    0000050
    585 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27755 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated ses… https://www.cve.org/CVERecord?id=CVE-2026-27755

    Post summary

    CVE-2026-27755 reveals a weak session identifier in SODOLA firmware, permitting attackers to forge authenticated sessions; no patch or exploitation details are provided.

    0000089
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27755 - Critical SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing pr... https://www.thehackerwire.com/vulnerability/CVE-2026-27755/ https://t.co/oHJyn3DfV8

    Post summary

    The tweet announces CVE‑2026‑27755, a critical weak session identifier flaw in SODOLA firmware that lets attackers forge authenticated sessions, but it does not provide a PoC, exploit, or patch details.

    0000026
    119 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWsodola-networksl902-swtgw124as---
OSsodola-networksl902-swtgw124as_firmware---

Explore more