ZeroHour

CVE-2024-9441

large

Unauthenticated OS Command Injection in Linear eMerge e3-Series Access Controllers

CVSS 3.1
9.8 critical
EPSS
53%p99
Published
()
Modified
AI analysis

CVE-2024-9441 is a critical OS command injection flaw (CWE-78) in Linear eMerge e3-Series access control controllers running version 1.00-07 and earlier. An unauthenticated remote attacker can send a crafted HTTP request to the forgot_password functionality, injecting arbitrary OS commands through the login_id parameter, which the controller then executes. Successful exploitation yields full command execution on the device, allowing the attacker to compromise the controller, access or alter credentials, and potentially pivot into the building's access control environment or the connected network. Any organization running an eMerge e3-Series controller at or below version 1.00-07 is affected, particularly units with their web interface reachable from the internet. As of disclosure, there is no known public proof-of-concept and the flaw is not in CISA KEV, but the high EPSS score (53.5%, 99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.

What to do: The headline reporting indicates the flaw is currently unpatched, so until Linear/Nortek ships a fix for versions beyond 1.00-07, restrict the controller's web interface to trusted management networks via firewall rules or VPN and avoid exposing the forgot_password endpoint to the internet. Check HTTP access logs for requests to the forgot_password functionality containing shell metacharacters or unexpected values in the login_id parameter, and monitor for anomalous commands on the device. Apply the vendor firmware update as soon as one becomes available.

Affected
Linear (Nortek Security & Control) eMerge e3-Series access control controllersall versions through 1.00-07 (inclusive)
Estimated exposure
largetens of thousands of deployed controllers (order of 10^4), with only a few thousand likely internet-exposed — eMerge e3-Series is a widely deployed commercial door-access platform, but such controllers are typically deployed on local building networks, so the directly internet-exposed population seen in public scans is far smaller (roughly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news