← Back to browse · API

CVE-2026-36356

Severity
CRITICAL
CVSS
9.1
EPSS
0.13549
Risk score
41.14
CISA KEV
No
PoC
Yes
Published
2026-05-05
Modified
2026-07-05
First seen
2026-08-07
Aliases
EUVD-2026-27327, GHSA-MWFR-MJ36-QV8W
Products
n/a:n/a n/a
Sources
euvd EUVD-2026-27327
packetstorm ba2873d782f80eda7bab3383|CVE-2026-36356

Description

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.

References