CVE-2024-9441
largeUnauthenticated OS Command Injection in Linear eMerge e3-Series Access Controllers
CVE-2024-9441 is a critical OS command injection flaw (CWE-78) in Linear eMerge e3-Series access control controllers running version 1.00-07 and earlier. An unauthenticated remote attacker can send a crafted HTTP request to the forgot_password functionality, injecting arbitrary OS commands through the login_id parameter, which the controller then executes. Successful exploitation yields full command execution on the device, allowing the attacker to compromise the controller, access or alter credentials, and potentially pivot into the building's access control environment or the connected network. Any organization running an eMerge e3-Series controller at or below version 1.00-07 is affected, particularly units with their web interface reachable from the internet. As of disclosure, there is no known public proof-of-concept and the flaw is not in CISA KEV, but the high EPSS score (53.5%, 99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.
What to do: The headline reporting indicates the flaw is currently unpatched, so until Linear/Nortek ships a fix for versions beyond 1.00-07, restrict the controller's web interface to trusted management networks via firewall rules or VPN and avoid exposing the forgot_password endpoint to the internet. Check HTTP access logs for requests to the forgot_password functionality containing shell metacharacters or unexpected values in the login_id parameter, and monitor for anomalous commands on the device. Apply the vendor firmware update as soon as one becomes available.
| Linear (Nortek Security & Control) eMerge e3-Series access control controllers | all versions through 1.00-07 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H