Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-48466 — Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control | Kitploit
Tools/GitHubGitHub/shipcod3/cve-2025-48466
IoT SecurityVulnerability AnalysisExploitationSCADA/ICS SecurityFuzzingNetwork SecurityPenetration TestingHardware & IoT Security
GitHubshipcod3/cve-2025-48466

CVE-2025-48466

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control

View Repository
21171 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-48466

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control. (see script: main.py)

Summary

I was able to figure out that it is just very easy to somehow manipulate the Modbus server running on an IoT Gateway for door control on a network. Any remote attacker without even having access to the admin panel of WISE-4060/LAN can execute the script and cause disruption or toggling of the Digital Output (DO) of the WISE-4060/LAN 4-channel Digital Input / 4-channel Relay Output IoT Ethernet I/O Module.

This vulnerability was discovered during our stint at SPIRITCYBER-24 IoT / OT Hackathon at Singapore.

Impact

Consequences: Remote attackers can execute Modbus commands to WISE-4060/LAN module and manipulate the DO channels. This could lead to unauthorized control of connected devices, such as turning systems on or off, causing disruptions or unsafe conditions.

In industrial settings, the DO channels might control critical systems like power relays, alarms, or machinery. In this case it is for door control .Unauthorized manipulation could lead to dangerous conditions, safety hazards, or equipment damage.

An attacker might capture valid Modbus commands and replay them later, causing unintended actions like toggling DO channels at inappropriate times.

main.py

Here is the output when running the script which fuzzes the addresses for the DO. Successful responses have 0x00 on the end while 0x02 is for fails.

image

PoC Video

https://github.com/user-attachments/assets/b0dccbd9-7974-430b-af5e-2198daf735db

Download Tool