GS110EMX¶
GS110EMX¶
A Plus switch: 10 ports, multi-gigabit uplinks, no PoE. Like every Plus model it has no SNMP agent, so NSDP and its web UI are the only ways in.
At a glance¶
Field |
Value |
|---|---|
Registry key |
|
Product name |
GS110EMX |
Class |
plus |
Ports |
10 |
PoE (PSE) ports |
0 |
Backends |
|
SNMP vendor subtree |
|
MAC/FDB table |
no |
Live-verified on units at 10.1.5.25–.27, firmware 1.0.2.8. Seed:
seed_gs110emx().
What works, over which protocol¶
Operation |
What it does |
||
|---|---|---|---|
Per-port link/admin status |
✓ |
✓ |
|
Per-port octet/packet counters |
✓ |
✓ |
|
VLAN list with tagged/untagged members |
✓ |
✓ |
|
Per-port PVID |
✓ |
✓ |
|
LLDP neighbour table |
|||
MAC/FDB forwarding table |
|||
Per-port PoE status and power draw |
|||
Fan/PSU/temperature sensors |
|||
Management IP configuration |
✓ |
✓ |
|
The switch’s host name |
✓ |
✓ |
|
Local login accounts and their access level |
|||
Which management services (http/https/telnet/ssh) are enabled |
|||
Remote-logging configuration and collectors |
|||
Full NSDP device record |
✓ |
||
Bring a port up or down |
✓ |
||
Enable or disable PoE on a port |
|||
Power-cycle a PoE port |
|||
Clear a latched PoE fault |
|||
Set or clear a port’s description |
✓ |
||
Force a port’s speed/duplex, or restore auto-negotiation |
|||
Turn IEEE 802.3x flow control on or off for a port |
|||
Set a port’s PVID |
✓ |
✓ |
|
Set a port tagged/untagged/excluded on a VLAN |
✓ |
✓ |
|
Create a VLAN |
✓ |
||
Delete a VLAN |
✓ |
||
Set the management IP/mask/gateway |
✓ |
||
Set the switch’s host name |
✓ |
✓ |
|
Turn remote logging on or off |
|||
Add a remote syslog collector |
|||
Remove a remote syslog collector |
|||
Upload an HTTPS certificate over the web UI |
|||
Deploy an HTTPS certificate via FASTPATH |
NSDP has no LLDP neighbour tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory)
model ‘gs110emx’ web UI has no page for get_lldp (LLDP neighbour table)
NSDP has no MAC/FDB table tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory)
model ‘gs110emx’ web UI has no page for get_macs (MAC/FDB forwarding table)
NSDP has no PoE status tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory); use the HTTP backend for PoE
model ‘gs110emx’ web UI has no page for get_poe (Per-port PoE status and power draw)
NSDP has no environmental-sensor tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory)
model ‘gs110emx’ web UI has no page for get_sensors (Fan/PSU/temperature sensors)
get_users is served only over CONSOLE, HTTP, SSH, TELNET
model ‘gs110emx’ web UI has no page for get_users (Local login accounts and their access level)
get_services is served only over CONSOLE, HTTP, SSH, TELNET
model ‘gs110emx’ web UI has no page for get_services (Which management services (http/https/telnet/ssh) are enabled)
get_syslog is served only over CONSOLE, HTTP, SNMP, SSH, TELNET
model ‘gs110emx’ web UI has no page for get_syslog (Remote-logging configuration and collectors)
nsdp_device is served only over NSDP
per-port admin-enable over NSDP is UNPROVEN on these Plus models: the measured tag inventory (GS110EMX fw 1.0.2.8) has two candidate per-port config tags (0x0800, 0x9400) whose semantics were never settled – no write has been attempted against either, and a wrong guess can drop the port’s link. Use the HTTP backend, whose port-settings page IS grounded
NSDP has no PoE control tag (measured by an exhaustive tag sweep of a real GS110EMX, 10.1.5.25 fw 1.0.2.8, 2026-07-30 – see nsdp_read._SWEEP); use the HTTP backend for PoE
model ‘gs110emx’ web UI has no page for set_poe (Enable or disable PoE on a port)
model ‘gs110emx’ web UI has no page for cycle_poe (Power-cycle a PoE port)
model ‘gs110emx’ web UI has no page for clear_poe_fault (Clear a latched PoE fault)
model ‘gs110emx’ web UI has no page for set_port_description (Set or clear a port’s description)
set_port_speed is served only over CONSOLE, HTTP, SSH, TELNET
model ‘gs110emx’ web UI has no page for set_port_speed (Force a port’s speed/duplex, or restore auto-negotiation)
model ‘gs110emx’ web UI carries no CSRF ‘hash’ token, which the HTTP create_vlan writer requires
model ‘gs110emx’ web UI carries no CSRF ‘hash’ token, which the HTTP delete_vlan writer requires
model ‘gs110emx’ web UI has no page for set_mgmt_ip (Set the management IP/mask/gateway)
remove_syslog_collector is served only over CONSOLE, HTTP, SNMP, SSH, TELNET
model ‘gs110emx’ web UI has no page for remove_syslog_collector (Remove a remote syslog collector)
upload_certificate is served only over HTTP
model ‘gs110emx’ web UI has no page for upload_certificate (Upload an HTTPS certificate over the web UI)
Measured behaviour¶
No MAC table, LLDP or sensors — on either interface. Established independently on both: an exhaustive sweep of the NSDP tag space against a live unit and the web UI’s page set, rather than measuring one and extrapolating to the other. The refusal messages name the sweep as their evidence.
NSDP v2 write authentication was cracked on this switch. It advertises
0x10 for tag 0x0014, meaning the salted challenge-response: read a
rotating 4-byte salt from 0x0017, then write an 8-byte XOR fold of the
password, the salt and the switch’s own MAC in tag 0x001A — first in the
packet, before the configuration TLVs, or it is rejected.
NSDP records the full investigation, including the
transforms that were tried and refused.
Every 10G link used to report as down. The PORT_STATUS speed byte value
0x06 means 10 Gbit/s; treating unknown values as “down” was a real defect,
found by the tag sweep and since fixed.
Its web UI uses the Gambit session scheme, and unlike NSDP it does expose
port administrative enable — which is why
set_port_enabled() works over HTTP but not
NSDP on this model.
Protocols¶
NSDP — the default backend.
HTTP web UI — the
GAMBITscheme,GS110EMXpage dialect.