Vulnerability record · CVE-2019-7255 · published 2 July 2019
CVE-2019-7255: Linear eMerge E3-Series devices cross-site scripting
Nortekcontrol · Linear Emerge Essential Firmware
Linear eMerge E3-Series devices are affected by a reflected cross-site scripting flaw (CWE-79). An attacker can inject script that executes in a victim's browser in the context of the affected device interface, which matters because these are physical access control systems where a compromised session can expose or alter administrative functions. The record gives no affected version detail beyond the product firmware names.
Description
Linear eMerge E3-Series devices allow XSS.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is a medium-severity XSS requiring user interaction, but the high EPSS score and public exploit code raise the practical risk for internet-exposed access control devices.
What it is
Linear eMerge E3-Series devices are affected by a reflected cross-site scripting flaw (CWE-79). An attacker can inject script that executes in a victim's browser in the context of the affected device interface, which matters because these are physical access control systems where a compromised session can expose or alter administrative functions. The record gives no affected version detail beyond the product firmware names.
Impact
An attacker can run script in a victim's authenticated browser session, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires the victim to trigger the crafted request (UI:R), typically via a malicious link or page. No authentication is needed to deliver the payload, though the victim's session context determines what the script can reach.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.558 (99th percentile) and public exploit references exist (Packet Storm, tagged Exploit), so weaponized proof-of-concept code is publicly available. No ransomware association is documented.
What to do
- Apply the vendor firmware update for Linear eMerge E3-Series; if no patch is available, isolate affected devices from untrusted networks.
- Place the device web interface behind a VPN or management network and never expose it directly to the internet.
- Enforce output encoding and input validation on the web interface if custom code or a WAF is in place.
- Restrict administrative access to the device and use dedicated, non-reused credentials.
- Monitor vendor advisories for updated firmware, since the record does not specify fixed versions.
Detection
- Inspect web server and proxy logs for script tags or encoded script payloads in request parameters to the eMerge web interface.
- Alert on requests to the device interface originating from external or unexpected source addresses.
- Review browser-side evidence of unexpected redirects or injected content on administrative sessions.
- Correlate access to the device UI with authentication events to spot session hijacking or anomalous admin activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155253/Linear-eMerge-E3-1.00-06-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Not ApplicableThird Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
| http://packetstormsecurity.com/files/155253/Linear-eMerge-E3-1.00-06-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Not ApplicableThird Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
Track CVE-2019-7255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.