Description
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Firmware can be updated over the network without authentication, which may allow remote code execution.
Published: 2017-02-13
Score: 9.8 Critical
EPSS: 7.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-10179 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Firmware can be updated over the network without authentication, which may allow remote code execution.
History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Moxa Nport 5100 Series Firmware Nport 5100a Series Firmware Nport 5110 Nport 5110a Nport 5130 Nport 5130a Nport 5150 Nport 5150a Nport 5150a1-m12 Nport 5150a1-m12-ct Nport 5150a1-m12-ct-t Nport 5150a1-m12-t Nport 5200 Series Firmware Nport 5200a Series Firmware Nport 5210 Nport 5210a Nport 5230 Nport 5230a Nport 5232 Nport 5232i Nport 5250a Nport 5250a1-m12 Nport 5250a1-m12-ct Nport 5250a1-m12-ct-t Nport 5250a1-m12-t Nport 5400 Series Firmware Nport 5410 Nport 5430 Nport 5430i Nport 5450 Nport 5450-t Nport 5450a1-m12 Nport 5450a1-m12-ct Nport 5450a1-m12-ct-t Nport 5450a1-m12-t Nport 5450i Nport 5450i-t Nport 5600-8-dtl Series Firmware Nport 5600 Series Firmware Nport 5610 Nport 5610-8-dtl Nport 5630 Nport 5650 Nport 5650-8-dtl Nport 5650i-8-dtl Nport 5x50a1-m12 Series Firmware Nport 6100 Series Firmware Nport 6150 Nport 6150-t Nport P5110a Nport P5150a Series Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-02T19:30:28.060Z

Reserved: 2016-11-16T00:00:00.000Z

Link: CVE-2016-9369

cve-icon Vulnrichment

Updated: 2024-08-06T02:50:36.981Z

cve-icon NVD

Status : Modified

Published: 2017-02-13T21:59:02.300

Modified: 2026-06-02T20:16:20.090

Link: CVE-2016-9369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function