Nortekcontrol's vulnerability profile centers on a focused line of access-control and security systems, particularly its Linear Emerge product family (Elite, Essential, and 5000P variants), which serve as entry points for physical security infrastructure in residential and commercial deployments. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the direct exposure of these devices to internet-facing attack surfaces and the high-value nature of physical-access control. The exposure recurs through a consistent set of structural weaknesses endemic to embedded security appliances: path traversal and OS command injection in management interfaces, hard-coded credentials in firmware, cross-site request forgery in web consoles, and insufficiently protected credential storage. Defenders should prioritize inventory and network isolation of affected Emerge devices, treat firmware updates as urgent, and restrict direct internet exposure of these systems; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nortekcontrol over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7256CRITICAL Linear eMerge E3-Series devices allow Command Injections. | Jul 2, 2019 | 9.8 | 99 | YES | YES |
CVE-2019-7254HIGH Linear eMerge E3-Series devices allow File Inclusion. | Jul 2, 2019 | 7.5 | 84 | NO | YES |
CVE-2019-7257CRITICAL Linear eMerge E3-Series devices allow Unrestricted File Upload. | Jul 2, 2019 | 10.0 | 79 | NO | YES |
CVE-2022-31499CRITICAL Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix fo | Aug 25, 2022 | 9.8 | 76 | NO | YES |
CVE-2019-7269CRITICAL Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. | Jul 2, 2019 | 9.8 | 66 | NO | YES |
CVE-2019-7255MEDIUM Linear eMerge E3-Series devices allow XSS. | Jul 2, 2019 | 6.1 | 63 | NO | YES |
CVE-2019-7265CRITICAL Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | Jul 2, 2019 | 9.8 | 53 | NO | YES |
CVE-2019-7267CRITICAL Linear eMerge 50P/5000P devices allow Cookie Path Traversal. | Jul 2, 2019 | 9.8 | 42 | NO | NO |
CVE-2019-7262HIGH Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | Jul 2, 2019 | 8.8 | 39 | NO | YES |
CVE-2022-31269HIGH Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the | Aug 25, 2022 | 8.2 | 38 | NO | YES |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nortekcontrol.
Media articles that mention a CVE ID that affects a product developed by Nortekcontrol — matched by CVE ID, not by vendor name.