CVE-2026-27752

Severity CVSS v4.0:
HIGH
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
27/02/2026
Last modified:
27/02/2026

Description

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administrative access to the gateway.