← Vulnerability feed

Vulnerability record · CVE-2019-7257 · published 2 July 2019

CVE-2019-7257: Linear eMerge E3-Series unrestricted file upload

Nortekcontrol · Linear Emerge Essential Firmware

Linear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded content can be executed, this flaw leads to remote code execution on the device. It matters because these are physical access control systems, so compromise can affect door control and connected infrastructure.

10.0 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-434 · Unrestricted file upload
10.0CVSS 3.1 base score, v2 7.5
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Linear eMerge E3-Series devices allow Unrestricted File Upload.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 10.0 with network reachability, no authentication, no user interaction, and public exploit code makes this a critical exposure for internet-facing devices.

What it is

Linear eMerge E3-Series devices accept unrestricted file uploads, allowing an attacker to place arbitrary files on the system. Because the uploaded content can be executed, this flaw leads to remote code execution on the device. It matters because these are physical access control systems, so compromise can affect door control and connected infrastructure.

Impact

An attacker can upload and execute arbitrary code, gaining control of the device at the privilege level of the web service, which the exploit reference describes as remote root code execution. This can lead to full compromise of the access control appliance.

Attack surface

The CVSS vector is network reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the upload endpoint is exposed to unauthenticated network clients. No authentication or victim action is required per the vector.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.69992, 99.3rd percentile) and a public exploit reference exists (Packet Storm, tagged Exploit), indicating mature public exploitation capability. No ransomware group usage is documented.

What to do

  • Apply the vendor firmware update for Linear eMerge E3-Series as soon as it is available; patch first.
  • Restrict network access to the device web interface to trusted management networks only.
  • Disable or block unauthenticated upload endpoints if the firmware allows it.
  • Place the device behind a firewall or VPN and remove any direct internet exposure.
  • Monitor the device for unexpected files or processes and reimage if compromise is suspected.

Detection

  • Monitor web server logs for POST requests to upload endpoints, especially from unexpected source IPs.
  • Alert on new or modified executable files in web-accessible directories on the device.
  • Watch for unexpected outbound connections or new listening services from the appliance.
  • Baseline normal device file system and process activity and alert on deviations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-7256Linear eMerge E3-Series access controllers OS command injectionLinear eMerge E3-Series access controller firmware is vulnerable to OS command injection (CWE-78), allowing commands to be run on the device. The fla…KEVEPSS 97%analysed9.8CVE-2019-7252Nortekcontrol linear emerge essential firmware insecure default initialization vulnerabilityLinear eMerge E3-Series devices have Default Credentials.EPSS 4.9%9.8CVE-2019-7253Nortekcontrol linear emerge essential firmware path traversal vulnerabilityLinear eMerge E3-Series devices allow Directory Traversal.EPSS 3.0%9.8CVE-2019-7260Nortekcontrol linear emerge essential firmware insufficiently protected credentials vulnerabilityLinear eMerge E3-Series devices have Cleartext Credentials in a Database.EPSS 6.6%9.8CVE-2019-7261Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices have Hard-coded Credentials.EPSS 5.5%9.8CVE-2019-7264Nortekcontrol linear emerge essential firmware out-of-bounds write vulnerabilityLinear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.EPSS 2.2%9.8CVE-2019-7265Nortekcontrol linear emerge essential firmware hard-coded credentials vulnerabilityLinear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).EPSS 23%9.8CVE-2019-7263Nortekcontrol linear emerge essential firmware vulnerabilityLinear eMerge E3-Series devices have a Version Control Failure.EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2019-7257), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.