CVE-2026-27757

7.1

Sodola Networks · SL902-SWTGW124AS

The Sodola SL902-SWTGW124AS switch firmware contains an unverified password change vulnerability, allowing authenticated users to modify account credentials without providing the current password.

Executive summary

An authenticated password change vulnerability in the Sodola SL902-SWTGW124AS switch allows attackers to hijack administrative accounts and maintain persistent unauthorized access.

Vulnerability

This vulnerability, categorized as CWE-620, permits any authenticated user to change the password of any account, including administrative accounts, without verifying the existing password. The flaw resides within the management interface and requires an active, authenticated session to trigger.

Business impact

Successful exploitation of this flaw can lead to a total compromise of the network switch management interface. By resetting account credentials, an attacker can gain persistent, unauthorized administrative access, potentially leading to unauthorized network traffic interception, configuration changes, or complete device takeover, justifying the 7.1 CVSS score.

Remediation

Immediate Action: Contact Sodola Networks support to obtain the latest firmware update that addresses this vulnerability, as a specific patch version is not currently listed in public records.

Proactive Monitoring: Monitor management interface access logs for unusual login patterns or frequent password change requests originating from non-administrative user accounts.

Compensating Controls: Restrict access to the switch management interface to trusted IP addresses only using access control lists, and ensure that management traffic is segmented from general user traffic.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized persistence within critical network infrastructure, administrators should prioritize securing the management interface of the affected switches. Until a firmware patch is confirmed and applied, limit administrative access to the device to mitigate the risk of exploitation by malicious actors.

More Sodola Networks CVEs

Sources

Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.