Description
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 transmit authentication credentials over unencrypted HTTP, allowing attackers to capture credentials. An attacker positioned to observe network traffic between a user and the device can intercept credentials and reuse them to gain administrative access to the gateway.
Problem types
CWE-319 Cleartext Transmission of Sensitive Information
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.sodola-network.com/...igmp-2-5gb-network-home-lab-switch
www.vulncheck.com/...124as-cleartext-credential-transmission