CVE-2016-9361

CRITICAL

Moxa UDP Device Discovery

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2016-9361. Includes Metasploit module auxiliary/admin/scada/moxa_credentials_recovery.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated information disclosure vulnerability in Moxa devices (CVE-2016-9361) to retrieve admin credentials and SNMP community strings via UDP port 4800. It supports multiple function codes for credential extraction and device enumeration.

Description

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Administration passwords can be retried without authenticating.

Exploits (2)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/scada/moxa_credentials_recovery.rb

This Metasploit module exploits an unauthenticated information disclosure vulnerability in Moxa devices (CVE-2016-9361) to retrieve admin credentials and SNMP community strings via UDP port 4800. It supports multiple function codes for credential extraction and device enumeration.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Moxa NPort, OnCell, and MGate devices (firmware versions older than 2017 or late 2016)
No auth needed
Prerequisites: Network access to UDP port 4800 on the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit SCANNER
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/scada/moxa_discover.rb

This Metasploit module scans for Moxa devices by sending a UDP discovery packet to port 4800 and checks for responses that match the Moxa protocol. It identifies devices that may be vulnerable to CVE-2016-9361, an information disclosure vulnerability.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Moxa NPort, OnCell, and MGate devices
No auth needed
Prerequisites: Network access to UDP port 4800
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-336-02
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/85965

Scores

CVSS v3 9.8
EPSS 0.4958
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287 CWE-307
Status published
Products (12)
None/Moxa NPort Moxa NPort
moxa/nport_5100_series_firmware < 2.5
moxa/nport_5100a_series_firmware < 1.2
moxa/nport_5200_series_firmware < 2.7
moxa/nport_5200a_series_firmware < 1.2
moxa/nport_5400_series_firmware < 3.10
moxa/nport_5600-8-dtl_series_firmware < 2.3
moxa/nport_5600_series_firmware < 3.6
moxa/nport_5x50a1-m12_series_firmware < 1.1
moxa/nport_6100_series_firmware < 1.13
... and 2 more
Published Feb 13, 2017
Tracked Since Feb 18, 2026