CVE-2019-7256
KEV PoC ×4moderateUnauthenticated OS Command Injection in Nice Linear eMerge E3 Access Controllers
CISA: Nice Linear eMerge E3-Series OS Command Injection Vulnerability
CVE-2019-7256 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the web interface of Nice/Nortek Control Linear eMerge E3-Series access control controllers. An unauthenticated remote attacker can send crafted HTTP requests to the controller's web endpoints — public proofs of concept target card_scan.php and card_scan_decoder.php on firmware 1.00-06 — causing arbitrary operating-system commands to run on the device. Successful exploitation yields full command execution on the controller, enabling takeover of the building access system and, as observed in the wild, conscription of exposed devices into DDoS botnets. Any site running Linear eMerge E3-Series Essential or Elite firmware is affected, especially controllers directly reachable from the internet. Exploitation is confirmed: public PoCs date to 2019, the bug was added to CISA's KEV catalog on 2024-03-25 amid reported active exploitation, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile).
What to do: Remove E3-Series controllers from direct internet exposure (restrict the web interface to management networks or VPN) and check exposed devices for signs of botnet compromise, such as unusual outbound traffic. Because CISA's required action is to remediate firmware per the vendor advisory, contact Nice/Nortek Control for current firmware and remediation guidance, and treat the flaw as actively exploited given the KEV listing and 97.1% EPSS.
| Nortek Control (Nice) Linear eMerge E3-Series Essential firmware | E3-Series devices; public PoCs reference firmware 1.00-06; no fixed version stated in the data |
| Nortek Control (Nice) Linear eMerge E3-Series Elite firmware | E3-Series devices; public PoCs reference firmware 1.00-06; no fixed version stated in the data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Linear eMerge E3-Series devices allow Command Injections.
- Affected
- Nice Linear eMerge E3-Series
- Required action
- Contact the vendor for guidance on remediating firmware, per their advisory.
- Due date
- Ransomware use
- Unknown
- Vendors
- nortekcontrol
- Products
- linear emerge essential firmware, linear emerge elite firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H