PatchDay Alert

CVE

CVE-2026-36356

0field notes · 1digest CVSS 9.1


Daily digests

An attacker can run arbitrary OS commands on MeiG Smart FORGE_SLT711 devices without any authentication by hitting the /action/SetRemoteAccessCfg endpoint on the built-in GoAhead web server. No credentials, no user interaction, just a crafted HTTP request gives full command execution. If these devices are reachable from the internet, you're already exposed.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.