← Vulnerability feed

Vulnerability record · CVE-2019-7256 · published 2 July 2019

CVE-2019-7256: Linear eMerge E3-Series access controllers OS command injection

Nortekcontrol · Linear Emerge Essential Firmware

Linear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The flaw is remotely reachable without authentication or user interaction, and the affected firmware versions are not specified in this record. It matters because these devices are physical access controllers, so compromise can affect door control and the network they sit on.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2024 EPSS 97% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
13References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Linear eMerge E3-Series devices allow Command Injections.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityUnauthenticated remote command injection with a 9.8 CVSS score, confirmed exploitation in CISA KEV, and a near-maximum EPSS probability.

What it is

Linear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The flaw is remotely reachable without authentication or user interaction, and the affected firmware versions are not specified in this record. It matters because these devices are physical access controllers, so compromise can affect door control and the network they sit on.

Impact

An unauthenticated attacker can execute arbitrary operating system commands on the controller, gaining full control of the device (CVSS 3.1 base 9.8, C:H/I:H/A:H). That control can be used to manipulate access control functions and pivot into the surrounding network.

Attack surface

Reachable over the network via the device's web interface, per the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-03-25, and EPSS gives a 30-day exploitation probability of 0.97136 (99.89th percentile). Multiple public exploit references exist, though no ransomware campaign use is documented.

What to do

  • Apply the firmware remediation the vendor (Nortek Control) directs; CISA's required action is to contact the vendor for guidance, as no fixed version is stated in this record.
  • If the device cannot be patched, isolate eMerge E3-Series controllers on a dedicated management VLAN with no internet exposure and strict allowlisting.
  • Restrict access to the controller web interface to trusted administrative hosts only.
  • Monitor vendor advisories for a fixed firmware release and track the CISA KEV due date (2024-04-15) for remediation status.

Detection

  • Inspect web server and application logs on the controller for command-injection patterns in request parameters, especially around card_scan.php and card_scan_decoder.php.
  • Alert on unexpected outbound connections or new processes spawned by the controller's web service.
  • Monitor for anomalous authentication or configuration changes on the access controller and correlated door-control events.
  • Use network monitoring to flag scanning or exploitation attempts against eMerge E3-Series management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-7256 to the Known Exploited Vulnerabilities catalog on 25 March 2024 as "Nice Linear eMerge E3-Series OS Command Injection Vulnerability". Required action: Contact the vendor for guidance on remediating firmware, per their advisory. Federal deadline 15 April 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/155255/Linear-eMerge-E3-1.00-06-card_scan.php-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155256/Linear-eMerge-E3-1.00-06-card_scan_decoder.php-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155272/Linear-eMerge-E3-Access-Controller-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/170372/Linear-eMerge-E3-Series-Access-Controller-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
https://applied-risk.com/labs/advisories Not Applicable
https://www.applied-risk.com/resources/ar-2019-005 Third Party Advisory
http://packetstormsecurity.com/files/155255/Linear-eMerge-E3-1.00-06-card_scan.php-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155256/Linear-eMerge-E3-1.00-06-card_scan_decoder.php-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155272/Linear-eMerge-E3-Access-Controller-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/170372/Linear-eMerge-E3-Series-Access-Controller-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
https://applied-risk.com/labs/advisories Not Applicable
https://www.applied-risk.com/resources/ar-2019-005 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7256 US Government Resource

Track CVE-2019-7256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-7257Linear eMerge E3-Series unrestricted file uploadLinear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded c…EPSS 70%analysed9.8CVE-2019-7252Nortekcontrol linear emerge essential firmware insecure default initialization vulnerabilityLinear eMerge E3-Series devices have Default Credentials.EPSS 4.9%9.8CVE-2019-7253Nortekcontrol linear emerge essential firmware path traversal vulnerabilityLinear eMerge E3-Series devices allow Directory Traversal.EPSS 3.0%9.8CVE-2019-7260Nortekcontrol linear emerge essential firmware insufficiently protected credentials vulnerabilityLinear eMerge E3-Series devices have Cleartext Credentials in a Database.EPSS 6.6%9.8CVE-2019-7261Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices have Hard-coded Credentials.EPSS 5.5%9.8CVE-2019-7264Nortekcontrol linear emerge essential firmware out-of-bounds write vulnerabilityLinear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.EPSS 2.2%9.8CVE-2019-7265Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).EPSS 23%9.8CVE-2019-7263Nortekcontrol linear emerge essential firmware vulnerabilityLinear eMerge E3-Series devices have a Version Control Failure.EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2019-7256), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.