CVE-2016-5799
Description
Moxa OnCell G3100V2, G3111, G3151, G3211, G3251 devices lack rate limiting on authentication, enabling remote brute-force attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Moxa OnCell G3100V2, G3111, G3151, G3211, G3251 devices lack rate limiting on authentication, enabling remote brute-force attacks.
Vulnerability
The affected Moxa OnCell devices do not properly restrict the number of authentication attempts, corresponding to CWE-307 (Improper Restriction of Excessive Authentication Attempts). This vulnerability affects the OnCell G3100V2 Series prior to firmware version 2.8, and the OnCell G3111, G3151, G3211, and G3251 Series prior to firmware version 1.7 [1].
Exploitation
An attacker can exploit this vulnerability remotely without any prior authentication. By sending a high volume of login requests, the attacker can perform a brute-force attack to guess valid credentials. The device does not implement rate limiting or account lockout mechanisms, allowing unlimited attempts until successful authentication is achieved [1].
Impact
Successful exploitation grants the attacker access to the device as a valid user. Depending on the privileges of the compromised account, the attacker may gain full administrative control over the cellular IP gateway, potentially leading to unauthorized access to connected serial or Ethernet devices, data exfiltration, or disruption of operations [1].
Mitigation
Moxa has released firmware updates to address this vulnerability: update OnCell G3100V2 devices to version 2.8 or later, and update OnCell G3111, G3151, G3211, and G3251 devices to version 1.7 or later [1]. No workarounds are documented in the available reference. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <2.8
- Range: <1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- ics-cert.us-cert.gov/advisories/ICSA-16-236-01nvdMitigationThird Party AdvisoryUS Government Resource
- www.securityfocus.com/bid/92606nvd
News mentions
0No linked articles in our index yet.