Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-9090-Modbus-TCP-Write-to-Read-Only-Coils-via-Function-Code-Spoofing — PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws. | Kitploit
Tools/GitHubGitHub/george0papasotiriou/cve-2026-9090-modbus-tcp-write-to-read-only-coils-via-function-code-spoofing
Vulnerability AnalysisExploitationSCADA/ICS SecurityNetwork SecurityPenetration TestingHardware & IoT SecurityMisconfiguration
GitHubgeorge0papasotiriou/cve-2026-9090-modbus-tcp-write-to-read-only-coils-via-function-code-spoofing

CVE-2026-9090-Modbus-TCP-Write-to-Read-Only-Coils-via-Function-Code-Spoofing

PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws.

View Repository
221 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-9090 – Modbus TCP Write to Read‑Only Coils via Function Code Spoofing

Program Code (Python with pymodbus simulation)

# modbus_plc_sim.py - Simulated Modbus PLC with read‑only coils
from pymodbus.server.sync import StartTcpServer
from pymodbus.device import ModbusDeviceIdentification
from pymodbus.datastore import ModbusSequentialDataBlock
from pymodbus.datastore import ModbusSlaveContext, ModbusServerContext

store = ModbusSlaveContext(
    di=ModbusSequentialDataBlock(0, [1]*100),  # coils – should be read‑only
    co=ModbusSequentialDataBlock(0, [0]*100),  # discrete inputs
    hr=ModbusSequentialDataBlock(0, [0]*100),
    ir=ModbusSequentialDataBlock(0, [0]*100)
)
# Vulnerability: coil block (di) is writable via function code 5 (Write Single Coil) normally, but maybe misconfigured.
# To simulate a flaw, we'll allow writing to coils using function code 15 (Write Multiple Coils) even though they should be read‑only.
# The pymodbus default allows writing to coils. We'll just demo writing to a coil that is supposed to be safety‑critical.
context = ModbusServerContext(slaves=store, single=True)
StartTcpServer(context, address=("0.0.0.0", 5020))

CVE-2026-9090 – Modbus TCP Write to Read‑Only Coils

Severity: Critical

Overview

An industrial PLC exposes coils that are intended to be read‑only (e.g., alarm states). However, due to a configuration error, the Modbus server accepts write commands (function code 5 or 15) to those coils, allowing an attacker to manipulate safety systems.

Vulnerability Details

  • Type: Insufficient Access Control
  • Impact: Physical damage, safety override.
  • Root Cause: The Modbus memory map is not properly configured to reject write commands for certain addresses.

Exploit Demonstration

  1. Start the simulated PLC:
    pip install pymodbus
    python modbus_plc_sim.py
    
  2. Run the exploit:
    python exploit_modbus_write.py
    
Download Tool