SODOLA SL902-SWTGW124AS Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the SODOLA SL902-SWTGW124AS firmware versions through 200.1.20. This vulnerability exists in the management interface, where attackers can trick authenticated users into submitting forged requests. These malicious requests can perform unauthorized configuration or administrative actions using the victim's privileges, but only when the authenticated user visits a malicious webpage.

Impact

Exploitation of this vulnerability allows for cross-site request forgery, where an attacker can perform actions on behalf of an authenticated user without their consent.

Remediation

Users can upgrade to the latest firmware version available for their specific switch model. For the SL902-SWTGW124AS model, the firmware version 200.1.30 is available. Instructions for upgrading the firmware are provided on the SODOLA website.

Added: Feb 27, 2026, 7:18 PM
Updated: Feb 27, 2026, 7:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.2
remediation
0.0
relevance
3.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.