VYPR
Vendor

Nortek

Products
3
CVEs
5
Across products
5
Status
Private

Products

3

Recent CVEs

5
  • CVE-2019-7265CriJul 2, 2019
    risk 0.69cvss 9.8epss 0.23

    Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).

  • CVE-2024-9441CriOct 2, 2024
    risk 0.68cvss 9.8epss 0.53

    The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

  • CVE-2019-7261CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.05

    Linear eMerge E3-Series devices have Hard-coded Credentials.

  • CVE-2019-7262HigJul 2, 2019
    risk 0.62cvss 8.8epss 0.16

    Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

  • CVE-2022-31269HigAug 25, 2022
    risk 0.54cvss 8.2epss 0.05

    Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)