← Vulnerability feed

Vulnerability record · CVE-2019-7255 · published 2 July 2019

CVE-2019-7255: Linear eMerge E3-Series devices cross-site scripting

Nortekcontrol · Linear Emerge Essential Firmware

Linear eMerge E3-Series devices are affected by a reflected cross-site scripting flaw (CWE-79). An attacker can inject script that executes in a victim's browser in the context of the affected device interface, which matters because these are physical access control systems where a compromised session can expose or alter administrative functions. The record gives no affected version detail beyond the product firmware names.

6.1 CVSS 3.1 Medium EPSS 56% · top 1.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Linear eMerge E3-Series devices allow XSS.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw is a medium-severity XSS requiring user interaction, but the high EPSS score and public exploit code raise the practical risk for internet-exposed access control devices.

What it is

Linear eMerge E3-Series devices are affected by a reflected cross-site scripting flaw (CWE-79). An attacker can inject script that executes in a victim's browser in the context of the affected device interface, which matters because these are physical access control systems where a compromised session can expose or alter administrative functions. The record gives no affected version detail beyond the product firmware names.

Impact

An attacker can run script in a victim's authenticated browser session, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires the victim to trigger the crafted request (UI:R), typically via a malicious link or page. No authentication is needed to deliver the payload, though the victim's session context determines what the script can reach.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.558 (99th percentile) and public exploit references exist (Packet Storm, tagged Exploit), so weaponized proof-of-concept code is publicly available. No ransomware association is documented.

What to do

  • Apply the vendor firmware update for Linear eMerge E3-Series; if no patch is available, isolate affected devices from untrusted networks.
  • Place the device web interface behind a VPN or management network and never expose it directly to the internet.
  • Enforce output encoding and input validation on the web interface if custom code or a WAF is in place.
  • Restrict administrative access to the device and use dedicated, non-reused credentials.
  • Monitor vendor advisories for updated firmware, since the record does not specify fixed versions.

Detection

  • Inspect web server and proxy logs for script tags or encoded script payloads in request parameters to the eMerge web interface.
  • Alert on requests to the device interface originating from external or unexpected source addresses.
  • Review browser-side evidence of unexpected redirects or injected content on administrative sessions.
  • Correlate access to the device UI with authentication events to spot session hijacking or anomalous admin activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7255 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-7256Linear eMerge E3-Series access controllers OS command injectionLinear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The fla…KEVEPSS 97%analysed10.0CVE-2019-7257Linear eMerge E3-Series unrestricted file uploadLinear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded c…EPSS 70%analysed9.8CVE-2019-7252Nortekcontrol linear emerge essential firmware insecure default initialization vulnerabilityLinear eMerge E3-Series devices have Default Credentials.EPSS 4.9%9.8CVE-2019-7253Nortekcontrol linear emerge essential firmware path traversal vulnerabilityLinear eMerge E3-Series devices allow Directory Traversal.EPSS 3.0%9.8CVE-2019-7260Nortekcontrol linear emerge essential firmware insufficiently protected credentials vulnerabilityLinear eMerge E3-Series devices have Cleartext Credentials in a Database.EPSS 6.6%9.8CVE-2019-7261Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices have Hard-coded Credentials.EPSS 5.5%9.8CVE-2019-7264Nortekcontrol linear emerge essential firmware out-of-bounds write vulnerabilityLinear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.EPSS 2.2%9.8CVE-2019-7265Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2019-7255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.