top of page
perceptive_background_267k.jpg

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action…

Published:

4 mei 2026 om 22:00:00

Alert date:

5 mei 2026 om 19:03:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies

The GoAhead web server running on MeiG Smart FORGE_SLT711 devices contains a critical vulnerability that allows unauthenticated OS command injection. The vulnerability exists in firmware version MDM9607.LE.1.0-00110-STD.PROD-1 and can be exploited through the /action/SetRemoteAccessCfg endpoint. This flaw enables remote attackers to execute arbitrary operating system commands without authentication. The vulnerability affects IoT devices that may be deployed in various network environments. Proof-of-concept code has been published on GitHub, increasing the risk of exploitation.

Technical details

Mitigation steps:

Affected products:

MeiG Smart FORGE_SLT711
GoAhead web server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page