Vulnerability record · CVE-2019-7254 · published 2 July 2019
CVE-2019-7254: Linear eMerge E3-Series file inclusion via path traversal
Nortekcontrol · Linear Emerge Essential Firmware
Linear eMerge E3-Series devices are vulnerable to file inclusion, classified as CWE-22 path traversal. An unauthenticated remote attacker can reach the flaw over the network, and successful exploitation exposes file contents, which matters because these devices are physical access controllers.
Description
Linear eMerge E3-Series devices allow File Inclusion.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure on internet-reachable access-control hardware, with very high EPSS despite no KEV listing.
What it is
Linear eMerge E3-Series devices are vulnerable to file inclusion, classified as CWE-22 path traversal. An unauthenticated remote attacker can reach the flaw over the network, and successful exploitation exposes file contents, which matters because these devices are physical access controllers.
Impact
An attacker gains read access to files on the device, with high confidentiality impact but no integrity or availability impact per the CVSS vector. Depending on what is exposed, this can leak configuration or credential material used for further access.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the device's web interface can attempt it. No authentication is required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high at 0.823 (99.6th percentile), indicating strong predicted exploitation activity. References are third-party advisories and a Packet Storm entry, with no public exploit tag in the record.
What to do
- Apply the vendor patch or fixed firmware for Linear eMerge E3-Series as soon as it is available; if none exists, isolate the devices.
- Place eMerge controllers behind a firewall or VPN and never expose their web interface to the internet.
- Restrict management access to trusted administrative networks and IP allowlists.
- Monitor vendor advisories from Nortek Control for updated firmware and interim guidance.
- If the device cannot be patched or segmented, consider replacing it or disabling remote management features.
Detection
- Review web server or device logs for traversal patterns such as ../ sequences or encoded variants in request paths.
- Alert on requests to the eMerge web interface from unexpected or external source IPs.
- Baseline normal file access on the device and flag reads of configuration or credential files outside normal behavior.
- Monitor network traffic to eMerge controllers for anomalous HTTP requests from non-administrative hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155252/Linear-eMerge-E3-1.00-06-Directory-Traversal.html | Third Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Third Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
| http://packetstormsecurity.com/files/155252/Linear-eMerge-E3-1.00-06-Directory-Traversal.html | Third Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Third Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
Track CVE-2019-7254 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7254), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.