← Vulnerability feed

Vulnerability record · CVE-2022-31499 · published 25 August 2022

CVE-2022-31499: Nortek Linear eMerge E3-Series OS command injection via ReaderNo

Nortekcontrol · Emerge E3 Firmware

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands through the ReaderNo parameter. The flaw is an incomplete fix for CVE-2019-7256, so the same attack path remains reachable on unpatched firmware. It matters because the device is a physical access control controller, and command execution there can compromise the door and alarm infrastructure it manages.

9.8 CVSS 3.1 Critical EPSS 65% · top 0.8% CWE-78 · OS command injection
9.8CVSS 3.1 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit references, and a very high EPSS score make this an urgent patch target despite the absence of KEV listing.

What it is

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands through the ReaderNo parameter. The flaw is an incomplete fix for CVE-2019-7256, so the same attack path remains reachable on unpatched firmware. It matters because the device is a physical access control controller, and command execution there can compromise the door and alarm infrastructure it manages.

Impact

An attacker gains remote OS command execution on the controller with the privileges of the vulnerable service, allowing full control of the device and any data or connected systems it can reach.

Attack surface

Reachable over the network via the web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed eMerge E3-Series management interface is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is 0.64589 (99.2nd percentile) and public exploit references exist (Packet Storm and a public gist), indicating exploit code is available and exploitation is plausible.

What to do

  • Upgrade eMerge E3-Series firmware to 0.32-08f or later, which is the version that addresses this incomplete fix.
  • If patching is not immediately possible, remove the management interface from untrusted networks and restrict access to a dedicated management VLAN with allowlisted source addresses.
  • Do not expose the controller web interface to the internet; place it behind a VPN or equivalent authenticated access layer.
  • Monitor vendor advisories for a follow-up fix, since this CVE is itself an incomplete fix for CVE-2019-7256 and further bypasses are possible.
  • Audit any other eMerge E3-Series endpoints still running firmware older than 0.32-08f and treat them as compromised until reviewed.

Detection

  • Inspect web server and application logs for requests to the ReaderNo parameter containing shell metacharacters such as semicolons, pipes, backticks, or command substitution syntax.
  • Monitor for unexpected child processes spawned by the eMerge web service, especially shells or common command interpreters.
  • Alert on outbound network connections from the controller to unfamiliar hosts, which may indicate command-and-control or data exfiltration after exploitation.
  • Review authentication and configuration change logs on the controller for activity that does not match known administrative sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5439Nortekcontrol emerge e3 firmware command injection vulnerabilityA Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arb…EPSS 4.2%8.2CVE-2022-31269Nortekcontrol emerge e3 firmware hard-coded credentials vulnerabilityNortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This…EPSS 7.0%6.1CVE-2022-31798Nortekcontrol emerge e3 firmware vulnerabilityNortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they ar…EPSS 8.5%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2022-31499), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.