


Perceptive Security
SOC/SIEM Consultancy

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action…
Published:
4 May 2026 at 22:00:00
Alert date:
5 May 2026 at 19:03:17
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies
The GoAhead web server running on MeiG Smart FORGE_SLT711 devices contains a critical vulnerability that allows unauthenticated OS command injection. The vulnerability exists in firmware version MDM9607.LE.1.0-00110-STD.PROD-1 and can be exploited through the /action/SetRemoteAccessCfg endpoint. This flaw enables remote attackers to execute arbitrary operating system commands without authentication. The vulnerability affects IoT devices that may be deployed in various network environments. Proof-of-concept code has been published on GitHub, increasing the risk of exploitation.
Technical details
Mitigation steps:
Affected products:
MeiG Smart FORGE_SLT711
GoAhead web server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-36356
http://forgeslt711.com
http://meig.com
https://github.com/totekuh/CVE-2026-36356
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
