{"cve":"CVE-2026-36356","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":null}],"enrichment":{"confidence":80.0,"confidence_source":"inferred","scores":[{"score":80.0,"source":"inferred"}]},"original":{"product":"n/a","source":"cna","vendor":"n/a"},"product":"goahead","vendor":"meig"}],"created":"2026-05-05T15:30:26.829598+00:00","updated":"2026-06-24T13:30:06.640639+00:00","vendors":["meig","meig$PRODUCT$goahead"]},"epss":{"score":0.03563},"mitre":{"cpes":[],"created":"2026-05-05T00:00:00+00:00","description":"The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/36xxx/CVE-2026-36356.json","references":["https://github.com/totekuh/CVE-2026-36356"],"title":null,"updated":"2026-07-05T16:16:35.278000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":[],"created":"2026-05-05T14:16:08.873000+00:00","description":"The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-36356.json","references":["https://github.com/totekuh/CVE-2026-36356"],"title":null,"updated":"2026-07-05T17:17:33.490000+00:00","vendors":[],"weaknesses":["CWE-306","CWE-78"]},"opencve":{"changes":[{"created":"2026-05-05T14:00:00+00:00","data":[{"details":{"new":"The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.","old":null},"type":"description"},{"details":{"added":["http://forgeslt711.com","http://meig.com","https://github.com/totekuh/CVE-2026-36356"],"removed":[]},"type":"references"}],"id":"a788d09e-a299-4b12-8cc7-67dce4e6e77e"},{"created":"2026-05-05T15:45:00+00:00","data":[{"details":{"new":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711","old":null},"type":"title"},{"details":{"added":["CWE-78"],"removed":[]},"type":"weaknesses"}],"id":"8a81b33f-8fc1-4581-81f8-f3e9aa0e4388"},{"created":"2026-05-05T18:15:00+00:00","data":[{"details":{"added":["CWE-306"],"removed":[]},"type":"weaknesses"},{"details":{"added":{"cvssV3_1":{"score":9.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6e46dafc-8526-4d0a-8f70-e52bf91f3358"},{"created":"2026-05-05T20:15:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711"},"type":"title"}],"id":"736d8c70-992b-44bf-98d6-a908e196cfa0"},{"created":"2026-05-06T09:45:00+00:00","data":[{"details":["meig","meig$PRODUCT$goahead"],"type":"first_time"},{"details":{"added":["meig","meig$PRODUCT$goahead"],"removed":[]},"type":"vendors"}],"id":"944c9b0f-fdd1-48d9-a3e1-4b810f0b5c3d"},{"created":"2026-05-28T15:15:00+00:00","data":[{"details":{"new":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711","old":null},"type":"title"}],"id":"47c6bf84-5804-4499-953d-2c6f481d2ba1"},{"created":"2026-06-16T13:45:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711"},"type":"title"}],"id":"b0e416de-65ad-4139-92b2-e0cdec3b3296"},{"created":"2026-06-17T11:15:00+00:00","data":[{"details":{"new":"Unauthenticated OS Command Injection via /action/SetRemoteAccessCfg Endpoint on GoAhead Web Server in MeiG Smart FORGE_SLT711 Device","old":null},"type":"title"}],"id":"266ea039-157d-452a-a8cb-c09c7065fad3"},{"created":"2026-06-18T16:45:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated OS Command Injection via /action/SetRemoteAccessCfg Endpoint on GoAhead Web Server in MeiG Smart FORGE_SLT711 Device"},"type":"title"}],"id":"23d4a1f1-4cdc-43a6-8c31-7d558d399746"},{"created":"2026-06-23T20:15:00+00:00","data":[{"details":{"new":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711","old":null},"type":"title"}],"id":"05395cfe-d16d-4e25-b4e9-6143b41819ba"},{"created":"2026-06-23T23:15:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711"},"type":"title"}],"id":"743b6d93-741d-4272-98bc-3a5d83342918"},{"created":"2026-06-24T03:45:00+00:00","data":[{"details":{"new":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711","old":null},"type":"title"}],"id":"2e4423ae-ab14-491e-99bb-e451dc403f0b"},{"created":"2026-06-24T06:00:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711"},"type":"title"}],"id":"3bbb78eb-266f-48fd-84ea-5c4b849939e4"},{"created":"2026-06-24T09:00:00+00:00","data":[{"details":{"new":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711","old":null},"type":"title"}],"id":"4ed4c084-95a8-4cf9-aae9-10859aaf150f"},{"created":"2026-06-24T13:45:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated OS Command Injection in GoAhead Web Server on MeiG Smart FORGE_SLT711"},"type":"title"}],"id":"8075d664-95a6-4132-9ee7-cc0cfe34275e"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-05-05T00:00:00+00:00","provider":"mitre"},"description":{"data":"The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.03563},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/totekuh/CVE-2026-36356"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":null,"provider":null},"updated":{"data":"2026-06-24T13:30:06.640639+00:00","provider":"enrichment"},"vendors":{"data":["meig","meig$PRODUCT$goahead"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-306","CWE-78"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-05-05T00:00:00+00:00","description":"The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":["https://github.com/totekuh/CVE-2026-36356"],"title":null,"updated":"2026-05-05T17:24:35.995000+00:00","vendors":[],"vulnrichment_repo_path":"2026/36xxx/CVE-2026-36356.json","weaknesses":["CWE-306","CWE-78"]}}