ZeroHour

Vulnerabilities

24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-31499
+2 in the same advisory: …31269 …31798
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo.

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

NVD description · AI analysis pending
9.8
group max
65% PoC ×2
  • nortekcontrol emerge e3 firmware
CVE-2019-7257
Linear eMerge E3-Series devices allow Unrestricted File Upload.

Linear eMerge E3-Series devices allow Unrestricted File Upload.

NVD description · AI analysis pending
10.0
group max
70% PoC
  • nortekcontrol linear emerge essential firmware
  • nortekcontrol linear emerge elite firmware
CVE-2019-7256
Unauthenticated OS Command Injection in Nice Linear eMerge E3 Access Controllers

CVE-2019-7256 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the web interface of Nice/Nortek Control Linear eMerge E3-Series access control controllers. An unauthenticated remote attacker can send crafted HTTP requests to the controller's web endpoints — public proofs of concept target card_scan.php and card_scan_decoder.php on firmware 1.00-06 — causing arbitrary operating-system commands to run on the device. Successful exploitation yields full command execution on the controller, enabling takeover of the building access system and, as observed in the wild, conscription of exposed devices into DDoS botnets. Any site running Linear eMerge E3-Series Essential or Elite firmware is affected, especially controllers directly reachable from the internet. Exploitation is confirmed: public PoCs date to 2019, the bug was added to CISA's KEV catalog on 2024-03-25 amid reported active exploitation, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile).

Do: Remove E3-Series controllers from direct internet exposure (restrict the web interface to management networks or VPN) and check exposed devices for signs of botnet compromise, such as unusual outbound traffic. Because CISA's required action is to remediate firmware per the vendor advisory, contact Nice/Nortek Control for current firmware and remediation guidance, and treat the flaw as actively exploited given the KEV listing and 97.1% EPSS.

9.897% KEV PoC ×4
  • Nortek Control (Nice) Linear eMerge E3-Series Essential firmware E3-Series devices; public PoCs reference firmware 1.00-06; no fixed version stated in the data
  • Nortek Control (Nice) Linear eMerge E3-Series Elite firmware E3-Series devices; public PoCs reference firmware 1.00-06; no fixed version stated in the data
moderatelow thousands of internet-exposed E3 controllers; installed base plausibly in the tens of thousands across commercial sites
CVE-2019-7269
+4 in the same advisory: …7268 …7267 …7266 …7270
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.

Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.

NVD description · AI analysis pending
9.8
group max
40% PoC
  • nortekcontrol linear emerge 50p firmware
  • nortekcontrol linear emerge 5000p firmware
CVE-2019-7271
Nortek Linear eMerge 50P/5000P devices have Default Credentials.

Nortek Linear eMerge 50P/5000P devices have Default Credentials.

NVD description · AI analysis pending
9.84%
  • nortekcontrol linear emerge 50p firmware
  • nortekcontrol linear emerge 5000p firmware
CVE-2018-5439
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior.

A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.

NVD description · AI analysis pending
9.84%
  • nortekcontrol emerge e3 firmware