Vulnerability record · CVE-2022-31499 · published 25 August 2022
CVE-2022-31499: Nortek Linear eMerge E3-Series OS command injection via ReaderNo
Nortekcontrol · Emerge E3 Firmware
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands through the ReaderNo parameter. The flaw is an incomplete fix for CVE-2019-7256, so the same attack path remains reachable on unpatched firmware. It matters because the device is a physical access control controller, and command execution there can compromise the door and alarm infrastructure it manages.
Description
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit references, and a very high EPSS score make this an urgent patch target despite the absence of KEV listing.
What it is
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands through the ReaderNo parameter. The flaw is an incomplete fix for CVE-2019-7256, so the same attack path remains reachable on unpatched firmware. It matters because the device is a physical access control controller, and command execution there can compromise the door and alarm infrastructure it manages.
Impact
An attacker gains remote OS command execution on the controller with the privileges of the vulnerable service, allowing full control of the device and any data or connected systems it can reach.
Attack surface
Reachable over the network via the web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed eMerge E3-Series management interface is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64589 (99.2nd percentile) and public exploit references exist (Packet Storm and a public gist), indicating exploit code is available and exploitation is plausible.
What to do
- Upgrade eMerge E3-Series firmware to 0.32-08f or later, which is the version that addresses this incomplete fix.
- If patching is not immediately possible, remove the management interface from untrusted networks and restrict access to a dedicated management VLAN with allowlisted source addresses.
- Do not expose the controller web interface to the internet; place it behind a VPN or equivalent authenticated access layer.
- Monitor vendor advisories for a follow-up fix, since this CVE is itself an incomplete fix for CVE-2019-7256 and further bypasses are possible.
- Audit any other eMerge E3-Series endpoints still running firmware older than 0.32-08f and treat them as compromised until reviewed.
Detection
- Inspect web server and application logs for requests to the ReaderNo parameter containing shell metacharacters such as semicolons, pipes, backticks, or command substitution syntax.
- Monitor for unexpected child processes spawned by the eMerge web service, especially shells or common command interpreters.
- Alert on outbound network connections from the controller to unfamiliar hosts, which may indicate command-and-control or data exfiltration after exploitation.
- Review authentication and configuration change logs on the controller for activity that does not match known administrative sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/167991/Nortek-Linear-eMerge-E3-Series-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://eg.linkedin.com/in/omar-1-hashem | Not Applicable |
| https://gist.github.com/omarhashem123/5f0c6f1394099b555740fdc5c7651ee2 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/167991/Nortek-Linear-eMerge-E3-Series-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://eg.linkedin.com/in/omar-1-hashem | Not Applicable |
| https://gist.github.com/omarhashem123/5f0c6f1394099b555740fdc5c7651ee2 | ExploitThird Party Advisory |
Track CVE-2022-31499 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31499), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.