Vulnerability record · CVE-2019-7256 · published 2 July 2019
CVE-2019-7256: Linear eMerge E3-Series access controllers OS command injection
Nortekcontrol · Linear Emerge Essential Firmware
Linear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The flaw is remotely reachable without authentication or user interaction, and the affected firmware versions are not specified in this record. It matters because these devices are physical access controllers, so compromise can affect door control and the network they sit on.
Description
Linear eMerge E3-Series devices allow Command Injections.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command injection with a 9.8 CVSS score, confirmed exploitation in CISA KEV, and a near-maximum EPSS probability.
What it is
Linear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The flaw is remotely reachable without authentication or user interaction, and the affected firmware versions are not specified in this record. It matters because these devices are physical access controllers, so compromise can affect door control and the network they sit on.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the controller, gaining full control of the device (CVSS 3.1 base 9.8, C:H/I:H/A:H). That control can be used to manipulate access control functions and pivot into the surrounding network.
Attack surface
Reachable over the network via the device's web interface, per the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2024-03-25, and EPSS gives a 30-day exploitation probability of 0.97136 (99.89th percentile). Multiple public exploit references exist, though no ransomware campaign use is documented.
What to do
- Apply the firmware remediation the vendor (Nortek Control) directs; CISA's required action is to contact the vendor for guidance, as no fixed version is stated in this record.
- If the device cannot be patched, isolate eMerge E3-Series controllers on a dedicated management VLAN with no internet exposure and strict allowlisting.
- Restrict access to the controller web interface to trusted administrative hosts only.
- Monitor vendor advisories for a fixed firmware release and track the CISA KEV due date (2024-04-15) for remediation status.
Detection
- Inspect web server and application logs on the controller for command-injection patterns in request parameters, especially around card_scan.php and card_scan_decoder.php.
- Alert on unexpected outbound connections or new processes spawned by the controller's web service.
- Monitor for anomalous authentication or configuration changes on the access controller and correlated door-control events.
- Use network monitoring to flag scanning or exploitation attempts against eMerge E3-Series management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7256 to the Known Exploited Vulnerabilities catalog on 25 March 2024 as "Nice Linear eMerge E3-Series OS Command Injection Vulnerability". Required action: Contact the vendor for guidance on remediating firmware, per their advisory. Federal deadline 15 April 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-7256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7256), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.