CVE-2026-27752
Severity CVSS v4.0:
HIGH
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
27/02/2026
Last modified:
27/02/2026
Description
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administrative access to the gateway.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
5.90
Severity 3.x
MEDIUM



