CVE-2022-31269 is a high-severity information disclosure vulnerability affecting Nortek Linear eMerge E3-Series devices, including their firmware, up to version 0.32-09c. It allows an unauthenticated attacker to retrieve administrative credentials from a publicly accessible /test.txt file, even if default credentials have been changed, potentially enabling unauthorized access to building doors. With a CVSS score of 8.2 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and direct impact on physical security. While there is no evidence of active exploitation or public Metasploit modules, Nuclei templates exist for detecting this flaw, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.32-09cCPE matchmatch criteria | cpe:2.3:o:nortekcontrol:emerge_e3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.