CVE-2026-36356

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
Configurations

No configuration.

History

05 May 2026, 18:16

Type Values Removed Values Added
CWE CWE-78
CWE-306
References () https://github.com/totekuh/CVE-2026-36356 - () https://github.com/totekuh/CVE-2026-36356 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

05 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 14:16

Updated : 2026-05-07 15:53


NVD link : CVE-2026-36356

Mitre link : CVE-2026-36356

CVE.ORG link : CVE-2026-36356


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-306

Missing Authentication for Critical Function