Vulnerability record · CVE-2019-7257 · published 2 July 2019
CVE-2019-7257: Linear eMerge E3-Series unrestricted file upload
Nortekcontrol · Linear Emerge Essential Firmware
Linear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded content can be executed, this flaw leads to remote code execution on the device. It matters because these are physical access control systems, so compromise can affect door control and connected infrastructure.
Description
Linear eMerge E3-Series devices allow Unrestricted File Upload.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, no user interaction, and public exploit code makes this a critical exposure for internet-facing devices.
What it is
Linear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded content can be executed, this flaw leads to remote code execution on the device. It matters because these are physical access control systems, so compromise can affect door control and connected infrastructure.
Impact
An attacker can upload and execute arbitrary code, gaining control of the device at the privilege level of the web service, which the exploit reference describes as remote root code execution. This can lead to full compromise of the access control appliance.
Attack surface
The CVSS vector is network reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the upload endpoint is exposed to unauthenticated network clients. No authentication or victim action is required per the vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.69992, 99.3rd percentile) and a public exploit reference exists (Packet Storm, tagged Exploit), indicating mature public exploitation capability. No ransomware group usage is documented.
What to do
- Apply the vendor firmware update for Linear eMerge E3-Series as soon as it is available; patch first.
- Restrict network access to the device web interface to trusted management networks only.
- Disable or block unauthenticated upload endpoints if the firmware allows it.
- Place the device behind a firewall or VPN and remove any direct internet exposure.
- Monitor the device for unexpected files or processes and reimage if compromise is suspected.
Detection
- Monitor web server logs for POST requests to upload endpoints, especially from unexpected source IPs.
- Alert on new or modified executable files in web-accessible directories on the device.
- Watch for unexpected outbound connections or new listening services from the appliance.
- Baseline normal device file system and process activity and alert on deviations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155254/Linear-eMerge-E3-1.00-06-Arbitrary-File-Upload-Remote-Root-Code-Execution.ht | ExploitThird Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Not ApplicableThird Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
| http://packetstormsecurity.com/files/155254/Linear-eMerge-E3-1.00-06-Arbitrary-File-Upload-Remote-Root-Code-Execution.ht | ExploitThird Party AdvisoryVDB Entry |
| https://applied-risk.com/labs/advisories | Not ApplicableThird Party Advisory |
| https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
Track CVE-2019-7257 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7257), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.