Junglewise Threat Intelligence

CVE-2026-36356: MeiG Smart FORGE_SLT711 unauthenticated command injection in GoAhead

CVE-2026-36356 · Severity: critical · CVSS 9.1 · Published 2026-05-05

Executive brief

MeiG Smart FORGE_SLT711 4G LTE routers contain a critical security flaw in their web management interface. An attacker can send a specially crafted request to the device to take complete control of it without needing a username or password. This could allow an unauthorized user to intercept network traffic, disrupt internet connectivity, or use the device as a foothold for further attacks on the local network.

Technical details

The vulnerability exists within a custom action handler in the GoAhead 3.x web server used by MeiG Smart FORGE_SLT711 routers. Two primary issues contribute to the flaw: first, the /action/SetRemoteAccessCfg endpoint is missing from the authenticated routes list in route.txt, allowing unauthenticated access (CWE-306). Second, the handler at offset 0x0003c6d8 uses sprintf() to interpolate the user-provided 'password' JSON field into a shell command string which is then executed via system() (CWE-78). Because the web server runs as root and does not sanitize input, a remote attacker can use shell metacharacters like $(...) to execute arbitrary commands with administrative privileges. Exploitation is 'blind,' meaning command output is not returned in the HTTP response.

Affected products

  • MeiG Smart Technology FORGE_SLT711 4G LTE CPE Router firmware MDM9607.LE.1.0-00110-STD.PROD-1

Timeline

  • 2026-05-03: disclosed: Vulnerability discovered by Daniil Gordeev
  • 2026-05-05: advisory: Initial CVE publication

References