ZeroHour

CVE-2019-7256

KEV PoC ×4moderate

Unauthenticated OS Command Injection in Nice Linear eMerge E3 Access Controllers

CISA: Nice Linear eMerge E3-Series OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2019-7256 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the web interface of Nice/Nortek Control Linear eMerge E3-Series access control controllers. An unauthenticated remote attacker can send crafted HTTP requests to the controller's web endpoints — public proofs of concept target card_scan.php and card_scan_decoder.php on firmware 1.00-06 — causing arbitrary operating-system commands to run on the device. Successful exploitation yields full command execution on the controller, enabling takeover of the building access system and, as observed in the wild, conscription of exposed devices into DDoS botnets. Any site running Linear eMerge E3-Series Essential or Elite firmware is affected, especially controllers directly reachable from the internet. Exploitation is confirmed: public PoCs date to 2019, the bug was added to CISA's KEV catalog on 2024-03-25 amid reported active exploitation, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile).

What to do: Remove E3-Series controllers from direct internet exposure (restrict the web interface to management networks or VPN) and check exposed devices for signs of botnet compromise, such as unusual outbound traffic. Because CISA's required action is to remediate firmware per the vendor advisory, contact Nice/Nortek Control for current firmware and remediation guidance, and treat the flaw as actively exploited given the KEV listing and 97.1% EPSS.

Affected
Nortek Control (Nice) Linear eMerge E3-Series Essential firmwareE3-Series devices; public PoCs reference firmware 1.00-06; no fixed version stated in the data
Nortek Control (Nice) Linear eMerge E3-Series Elite firmwareE3-Series devices; public PoCs reference firmware 1.00-06; no fixed version stated in the data
Estimated exposure
moderatelow thousands of internet-exposed E3 controllers; installed base plausibly in the tens of thousands across commercial sites — Estimated from deployment patterns and historical public internet scans: these are IP door-access panels typically installed one or more per commercial site, with only a few thousand eMerge controllers observed directly exposed online at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Linear eMerge E3-Series devices allow Command Injections.

CISA Known Exploited Vulnerability
Affected
Nice Linear eMerge E3-Series
Required action
Contact the vendor for guidance on remediating firmware, per their advisory.
Due date
Ransomware use
Unknown
Vendors
nortekcontrol
Products
linear emerge essential firmware, linear emerge elite firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news