CVE-2026-27757
7.1Sodola Networks · SL902-SWTGW124AS
The Sodola SL902-SWTGW124AS switch firmware contains an unverified password change vulnerability, allowing authenticated users to modify account credentials without providing the current password.
Executive summary
An authenticated password change vulnerability in the Sodola SL902-SWTGW124AS switch allows attackers to hijack administrative accounts and maintain persistent unauthorized access.
Vulnerability
This vulnerability, categorized as CWE-620, permits any authenticated user to change the password of any account, including administrative accounts, without verifying the existing password. The flaw resides within the management interface and requires an active, authenticated session to trigger.
Business impact
Successful exploitation of this flaw can lead to a total compromise of the network switch management interface. By resetting account credentials, an attacker can gain persistent, unauthorized administrative access, potentially leading to unauthorized network traffic interception, configuration changes, or complete device takeover, justifying the 7.1 CVSS score.
Remediation
Immediate Action: Contact Sodola Networks support to obtain the latest firmware update that addresses this vulnerability, as a specific patch version is not currently listed in public records.
Proactive Monitoring: Monitor management interface access logs for unusual login patterns or frequent password change requests originating from non-administrative user accounts.
Compensating Controls: Restrict access to the switch management interface to trusted IP addresses only using access control lists, and ensure that management traffic is segmented from general user traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized persistence within critical network infrastructure, administrators should prioritize securing the management interface of the affected switches. Until a firmware patch is confirmed and applied, limit administrative access to the device to mitigate the risk of exploitation by malicious actors.
More Sodola Networks CVEs
Sources
Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.