Sodola Network's vulnerability footprint concentrates on a narrowly scoped networking appliance, the SL902 Secure Gateway product line and its associated firmware. The disclosure pattern reflects the device's role as a gateway component; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sodola Network over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27755CRITICAL SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by compu | Feb 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-27751CRITICAL SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the managemen | Feb 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-27757HIGH SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the | Feb 27, 2026 | 7.2 | 23 | NO | NO |
CVE-2026-27754MEDIUM SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakening session security. Attackers c | Feb 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-27753MEDIUM SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows remote attackers to perform unlimited login attempts against t | Feb 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-27758MEDIUM SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authentica | Feb 27, 2026 | 6.5 | 20 | NO | NO |
CVE-2026-27752MEDIUM SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positio | Feb 27, 2026 | 5.9 | 20 | NO | NO |
CVE-2026-27756MEDIUM SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encod | Feb 27, 2026 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sodola Network.
Media articles that mention a CVE ID that affects a product developed by Sodola Network — matched by CVE ID, not by vendor name.