CVE-2026-36356
the affected product
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
- CVSS
- 9.1
- EPSS
- 13.5% 96.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.05