SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visited by authenticated users.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-02-27 19:16
Updated : 2026-03-03 19:12
NVD link : CVE-2026-27756
Mitre link : CVE-2026-27756
CVE.ORG link : CVE-2026-27756
JSON object : View
Products Affected
sodola-network
- sl902-swtgw124as_firmware
- sl902-swtgw124as
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
