Vulnerability record · CVE-2018-5439 · published 19 February 2018
CVE-2018-5439: Nortekcontrol emerge e3 firmware command injection vulnerability
Nortekcontrol · Emerge E3 Firmware
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.
Description
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-18-046-01 | Third Party AdvisoryUS Government Resource |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-046-01 | Third Party AdvisoryUS Government Resource |
Track CVE-2018-5439 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-5439), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.