GS110EMX

GS110EMX switch

GS110EMX

12345678910PoE (0)no PoE (10)
Port map as the library addresses these ports — schematic, not a faceplate layout.

A Plus switch: 10 ports, multi-gigabit uplinks, no PoE. Like every Plus model it has no SNMP agent, so NSDP and its web UI are the only ways in.

At a glance

Field

Value

Registry key

gs110emx

Product name

GS110EMX

Class

plus

Ports

10

PoE (PSE) ports

0

Backends

NSDP, HTTP

SNMP vendor subtree

none (standard MIBs only)

MAC/FDB table

no

Live-verified on units at 10.1.5.25–.27, firmware 1.0.2.8. Seed: seed_gs110emx().

What works, over which protocol

Operation

What it does

NSDP

HTTP

get_ports

Per-port link/admin status

✓

✓

get_stats

Per-port octet/packet counters

✓

✓

get_vlans

VLAN list with tagged/untagged members

✓

✓

get_pvids

Per-port PVID

✓

✓

get_lldp

LLDP neighbour table

— [gs110emx-1]

— [gs110emx-2]

get_macs

MAC/FDB forwarding table

— [gs110emx-3]

— [gs110emx-4]

get_poe

Per-port PoE status and power draw

— [gs110emx-5]

— [gs110emx-6]

get_sensors

Fan/PSU/temperature sensors

— [gs110emx-7]

— [gs110emx-8]

get_mgmt_ip

Management IP configuration

✓

✓

get_hostname

The switch’s host name

✓

✓

get_users

Local login accounts and their access level

— [gs110emx-9]

— [gs110emx-10]

get_services

Which management services (http/https/telnet/ssh) are enabled

— [gs110emx-11]

— [gs110emx-12]

get_syslog

Remote-logging configuration and collectors

— [gs110emx-13]

— [gs110emx-14]

nsdp_device

Full NSDP device record

✓

— [gs110emx-15]

set_port_enabled

Bring a port up or down

— [gs110emx-16]

✓

set_poe

Enable or disable PoE on a port

— [gs110emx-17]

— [gs110emx-18]

cycle_poe

Power-cycle a PoE port

— [gs110emx-17]

— [gs110emx-19]

clear_poe_fault

Clear a latched PoE fault

— [gs110emx-17]

— [gs110emx-20]

set_port_description

Set or clear a port’s description

✓

— [gs110emx-21]

set_port_speed

Force a port’s speed/duplex, or restore auto-negotiation

— [gs110emx-22]

— [gs110emx-23]

set_flow_control

Turn IEEE 802.3x flow control on or off for a port

— [gs110emx-24]

— [gs110emx-24]

set_pvid

Set a port’s PVID

✓

✓

set_vlan_membership

Set a port tagged/untagged/excluded on a VLAN

✓

✓

create_vlan

Create a VLAN

✓

— [gs110emx-25]

delete_vlan

Delete a VLAN

✓

— [gs110emx-26]

set_mgmt_ip

Set the management IP/mask/gateway

✓

— [gs110emx-27]

set_hostname

Set the switch’s host name

✓

✓

set_syslog_enabled

Turn remote logging on or off

— [gs110emx-28]

— [gs110emx-28]

add_syslog_collector

Add a remote syslog collector

— [gs110emx-29]

— [gs110emx-29]

remove_syslog_collector

Remove a remote syslog collector

— [gs110emx-30]

— [gs110emx-31]

upload_certificate

Upload an HTTPS certificate over the web UI

— [gs110emx-32]

— [gs110emx-33]

upload_certificate_scp

Deploy an HTTPS certificate via FASTPATH copy scp://

— [gs110emx-34]

— [gs110emx-34]

[gs110emx-1]

NSDP has no LLDP neighbour tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory)

[gs110emx-2]

model ‘gs110emx’ web UI has no page for get_lldp (LLDP neighbour table)

[gs110emx-3]

NSDP has no MAC/FDB table tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory)

[gs110emx-4]

model ‘gs110emx’ web UI has no page for get_macs (MAC/FDB forwarding table)

[gs110emx-5]

NSDP has no PoE status tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory); use the HTTP backend for PoE

[gs110emx-6]

model ‘gs110emx’ web UI has no page for get_poe (Per-port PoE status and power draw)

[gs110emx-7]

NSDP has no environmental-sensor tag (measured by an exhaustive NSDP tag sweep of a real GS110EMX (10.1.5.25, firmware 1.0.2.8, 2026-07-30) covering every tag in the 16-bit space; see nsdp_read.py for the full tag inventory)

[gs110emx-8]

model ‘gs110emx’ web UI has no page for get_sensors (Fan/PSU/temperature sensors)

[gs110emx-9]

get_users is served only over CONSOLE, HTTP, SSH, TELNET

[gs110emx-10]

model ‘gs110emx’ web UI has no page for get_users (Local login accounts and their access level)

[gs110emx-11]

get_services is served only over CONSOLE, HTTP, SSH, TELNET

[gs110emx-12]

model ‘gs110emx’ web UI has no page for get_services (Which management services (http/https/telnet/ssh) are enabled)

[gs110emx-13]

get_syslog is served only over CONSOLE, HTTP, SNMP, SSH, TELNET

[gs110emx-14]

model ‘gs110emx’ web UI has no page for get_syslog (Remote-logging configuration and collectors)

[gs110emx-15]

nsdp_device is served only over NSDP

[gs110emx-16]

per-port admin-enable over NSDP is UNPROVEN on these Plus models: the measured tag inventory (GS110EMX fw 1.0.2.8) has two candidate per-port config tags (0x0800, 0x9400) whose semantics were never settled – no write has been attempted against either, and a wrong guess can drop the port’s link. Use the HTTP backend, whose port-settings page IS grounded

[gs110emx-17] (1,2,3)

NSDP has no PoE control tag (measured by an exhaustive tag sweep of a real GS110EMX, 10.1.5.25 fw 1.0.2.8, 2026-07-30 – see nsdp_read._SWEEP); use the HTTP backend for PoE

[gs110emx-18]

model ‘gs110emx’ web UI has no page for set_poe (Enable or disable PoE on a port)

[gs110emx-19]

model ‘gs110emx’ web UI has no page for cycle_poe (Power-cycle a PoE port)

[gs110emx-20]

model ‘gs110emx’ web UI has no page for clear_poe_fault (Clear a latched PoE fault)

[gs110emx-21]

model ‘gs110emx’ web UI has no page for set_port_description (Set or clear a port’s description)

[gs110emx-22]

set_port_speed is served only over CONSOLE, HTTP, SSH, TELNET

[gs110emx-23]

model ‘gs110emx’ web UI has no page for set_port_speed (Force a port’s speed/duplex, or restore auto-negotiation)

[gs110emx-24] (1,2)

set_flow_control is served only over CONSOLE, SSH, TELNET

[gs110emx-25]

model ‘gs110emx’ web UI carries no CSRF ‘hash’ token, which the HTTP create_vlan writer requires

[gs110emx-26]

model ‘gs110emx’ web UI carries no CSRF ‘hash’ token, which the HTTP delete_vlan writer requires

[gs110emx-27]

model ‘gs110emx’ web UI has no page for set_mgmt_ip (Set the management IP/mask/gateway)

[gs110emx-28] (1,2)

set_syslog_enabled is served only over CONSOLE, SNMP, SSH, TELNET

[gs110emx-29] (1,2)

add_syslog_collector is served only over CONSOLE, SSH, TELNET

[gs110emx-30]

remove_syslog_collector is served only over CONSOLE, HTTP, SNMP, SSH, TELNET

[gs110emx-31]

model ‘gs110emx’ web UI has no page for remove_syslog_collector (Remove a remote syslog collector)

[gs110emx-32]

upload_certificate is served only over HTTP

[gs110emx-33]

model ‘gs110emx’ web UI has no page for upload_certificate (Upload an HTTPS certificate over the web UI)

[gs110emx-34] (1,2)

upload_certificate_scp is served only over CONSOLE, SSH, TELNET

Measured behaviour

No MAC table, LLDP or sensors — on either interface. Established independently on both: an exhaustive sweep of the NSDP tag space against a live unit and the web UI’s page set, rather than measuring one and extrapolating to the other. The refusal messages name the sweep as their evidence.

NSDP v2 write authentication was cracked on this switch. It advertises 0x10 for tag 0x0014, meaning the salted challenge-response: read a rotating 4-byte salt from 0x0017, then write an 8-byte XOR fold of the password, the salt and the switch’s own MAC in tag 0x001A — first in the packet, before the configuration TLVs, or it is rejected. NSDP records the full investigation, including the transforms that were tried and refused.

Every 10G link used to report as down. The PORT_STATUS speed byte value 0x06 means 10 Gbit/s; treating unknown values as “down” was a real defect, found by the tag sweep and since fixed.

Its web UI uses the Gambit session scheme, and unlike NSDP it does expose port administrative enable — which is why set_port_enabled() works over HTTP but not NSDP on this model.

Protocols