PatchSiren cyber security CVE debrief
CVE-2016-9333 Moxa CVE debrief
CVE-2016-9333 is a critical SQL injection vulnerability in Moxa SoftCMS versions prior to 1.6. According to the NVD record, the issue can allow a remote attacker to access SoftCMS with administrator privileges through specially crafted input. The NVD assigns CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating network-reachable, no-authentication exploitation with severe confidentiality, integrity, and availability impact.
- Vendor
- Moxa
- Product
- Softcms
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2016-08-21
- Original CVE updated
- 2025-06-05
- Advisory published
- 2016-08-21
- Advisory updated
- 2025-06-05
Who should care
Organizations running Moxa SoftCMS, especially versions 1.5 and earlier, should treat this as a high-priority issue. Security teams, OT/ICS administrators, and anyone exposing SoftCMS to untrusted networks should review affected deployments immediately.
Technical summary
The NVD entry maps this issue to CWE-89 (SQL Injection) and marks cpe:2.3:a:moxa:softcms:* with vulnerable versions through 1.5. The vulnerability is described as improper input sanitization in the SoftCMS application, which may let a remote attacker inject SQL and obtain administrator-level access. The CVSS vector shows no privileges or user interaction required, consistent with a remotely exploitable application flaw.
Defensive priority
Critical. The combination of remote exploitability, no authentication requirement, and full CIA impact makes this a top-priority remediation item for any exposed or operational SoftCMS instance.
Recommended defensive actions
- Identify all Moxa SoftCMS deployments and confirm whether any instance is running version 1.5 or earlier.
- Upgrade to SoftCMS version 1.6 or later, which is outside the affected range listed in the NVD record.
- If immediate upgrading is not possible, restrict network exposure to trusted management networks and limit access as much as operationally feasible.
- Review application and database logs for unexpected SQL activity or abnormal administrator logins tied to SoftCMS.
- Apply layered controls such as segmentation and access filtering to reduce reachability from untrusted networks.
- Reassess any remote administration paths that could expose SoftCMS to attackers and remove unnecessary exposure.
Evidence notes
This debrief is based only on the supplied NVD-derived corpus and official links. The source record states that Moxa SoftCMS prior to version 1.6 is affected, describes the flaw as a SQL injection that can grant administrator privilege, and lists CWE-89 with CVSS 3.0 9.8. The record also cites ICS-CERT advisory ICSA-16-322-02 and SecurityFocus BID 94394 as references, but no additional claims are made beyond the supplied text.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9333 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9333
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9333 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9333
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-16-322-02
[email protected] - Mitigation, Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.