← Vulnerability feed

Vulnerability record · CVE-2019-7254 · published 2 July 2019

CVE-2019-7254: Linear eMerge E3-Series file inclusion via path traversal

Nortekcontrol · Linear Emerge Essential Firmware

Linear eMerge E3-Series devices are vulnerable to file inclusion, classified as CWE-22 path traversal. An unauthenticated remote attacker can reach the flaw over the network, and successful exploitation exposes file contents, which matters because these devices are physical access controllers.

7.5 CVSS 3.1 High EPSS 82% · top 0.3% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Linear eMerge E3-Series devices allow File Inclusion.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote file disclosure on internet-reachable access-control hardware, with very high EPSS despite no KEV listing.

What it is

Linear eMerge E3-Series devices are vulnerable to file inclusion, classified as CWE-22 path traversal. An unauthenticated remote attacker can reach the flaw over the network, and successful exploitation exposes file contents, which matters because these devices are physical access controllers.

Impact

An attacker gains read access to files on the device, with high confidentiality impact but no integrity or availability impact per the CVSS vector. Depending on what is exposed, this can leak configuration or credential material used for further access.

Attack surface

Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the device's web interface can attempt it. No authentication is required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high at 0.823 (99.6th percentile), indicating strong predicted exploitation activity. References are third-party advisories and a Packet Storm entry, with no public exploit tag in the record.

What to do

  • Apply the vendor patch or fixed firmware for Linear eMerge E3-Series as soon as it is available; if none exists, isolate the devices.
  • Place eMerge controllers behind a firewall or VPN and never expose their web interface to the internet.
  • Restrict management access to trusted administrative networks and IP allowlists.
  • Monitor vendor advisories from Nortek Control for updated firmware and interim guidance.
  • If the device cannot be patched or segmented, consider replacing it or disabling remote management features.

Detection

  • Review web server or device logs for traversal patterns such as ../ sequences or encoded variants in request paths.
  • Alert on requests to the eMerge web interface from unexpected or external source IPs.
  • Baseline normal file access on the device and flag reads of configuration or credential files outside normal behavior.
  • Monitor network traffic to eMerge controllers for anomalous HTTP requests from non-administrative hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7254 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-7256Linear eMerge E3-Series access controllers OS command injectionLinear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The fla…KEVEPSS 97%analysed10.0CVE-2019-7257Linear eMerge E3-Series unrestricted file uploadLinear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded c…EPSS 70%analysed9.8CVE-2019-7252Nortekcontrol linear emerge essential firmware insecure default initialization vulnerabilityLinear eMerge E3-Series devices have Default Credentials.EPSS 4.9%9.8CVE-2019-7253Nortekcontrol linear emerge essential firmware path traversal vulnerabilityLinear eMerge E3-Series devices allow Directory Traversal.EPSS 3.0%9.8CVE-2019-7260Nortekcontrol linear emerge essential firmware insufficiently protected credentials vulnerabilityLinear eMerge E3-Series devices have Cleartext Credentials in a Database.EPSS 6.6%9.8CVE-2019-7261Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices have Hard-coded Credentials.EPSS 5.5%9.8CVE-2019-7264Nortekcontrol linear emerge essential firmware out-of-bounds write vulnerabilityLinear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.EPSS 2.2%9.8CVE-2019-7265Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2019-7254), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.