CVE-2026-36356

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-05 14:16

Updated : 2026-07-05 17:17


NVD link : CVE-2026-36356

Mitre link : CVE-2026-36356

CVE.ORG link : CVE-2026-36356


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-306

Missing Authentication for Critical Function