Vendor
Nortek
Products
3
CVEs
5
Across products
5
Status
Private
Products
3- 3 CVEs
- 2 CVEs
- 0 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-7265 | Cri | 0.69 | 9.8 | 0.23 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | ||
| CVE-2024-9441 | Cri | 0.68 | 9.8 | 0.53 | Oct 2, 2024 | The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP. | ||
| CVE-2019-7261 | Cri | 0.64 | 9.8 | 0.05 | Jul 2, 2019 | Linear eMerge E3-Series devices have Hard-coded Credentials. | ||
| CVE-2019-7262 | Hig | 0.62 | 8.8 | 0.16 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | ||
| CVE-2022-31269 | Hig | 0.54 | 8.2 | 0.05 | Aug 25, 2022 | Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.) |
- risk 0.69cvss 9.8epss 0.23
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
- risk 0.68cvss 9.8epss 0.53
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
- risk 0.64cvss 9.8epss 0.05
Linear eMerge E3-Series devices have Hard-coded Credentials.
- risk 0.62cvss 8.8epss 0.16
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
- risk 0.54cvss 8.2epss 0.05
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)