nortekcontrol CVE Vulnerabilities & Metrics

Focus on nortekcontrol vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About nortekcontrol Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with nortekcontrol. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total nortekcontrol CVEs: 24
Earliest CVE date: 19 Feb 2018, 18:29 UTC
Latest CVE date: 25 Aug 2022, 23:15 UTC

Latest CVE reference: CVE-2022-31798

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical nortekcontrol CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.5

Max CVSS: 10.0

Critical CVEs (≥9): 7

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 9
7.0-8.9 5
9.0-10.0 7

CVSS Distribution Chart

Top 5 Highest CVSS nortekcontrol CVEs

These are the five CVEs with the highest CVSS scores for nortekcontrol, sorted by severity first and recency.

All CVEs for nortekcontrol

CVE-2022-31798 nortekcontrol vulnerability CVSS: 0 25 Aug 2022, 23:15 UTC

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

CVE-2022-31499 nortekcontrol vulnerability CVSS: 0 25 Aug 2022, 23:15 UTC

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

CVE-2022-31269 nortekcontrol vulnerability CVSS: 0 25 Aug 2022, 22:15 UTC

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

CVE-2019-7258 nortekcontrol vulnerability CVSS: 6.5 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices allow Privilege Escalation.

CVE-2019-7257 nortekcontrol vulnerability CVSS: 7.5 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices allow Unrestricted File Upload.

CVE-2019-7256 nortekcontrol vulnerability CVSS: 10.0 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices allow Command Injections.

CVE-2019-7255 nortekcontrol vulnerability CVSS: 4.3 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices allow XSS.

CVE-2019-7254 nortekcontrol vulnerability CVSS: 5.0 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices allow File Inclusion.

CVE-2019-7253 nortekcontrol vulnerability CVSS: 7.5 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices allow Directory Traversal.

CVE-2019-7252 nortekcontrol vulnerability CVSS: 5.0 02 Jul 2019, 19:15 UTC

Linear eMerge E3-Series devices have Default Credentials.

CVE-2019-7262 nortekcontrol vulnerability CVSS: 6.8 02 Jul 2019, 18:15 UTC

Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

CVE-2019-7261 nortekcontrol vulnerability CVSS: 10.0 02 Jul 2019, 18:15 UTC

Linear eMerge E3-Series devices have Hard-coded Credentials.

CVE-2019-7260 nortekcontrol vulnerability CVSS: 5.0 02 Jul 2019, 18:15 UTC

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

CVE-2019-7259 nortekcontrol vulnerability CVSS: 4.0 02 Jul 2019, 18:15 UTC

Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.

CVE-2019-7270 nortekcontrol vulnerability CVSS: 6.8 02 Jul 2019, 17:15 UTC

Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).

CVE-2019-7269 nortekcontrol vulnerability CVSS: 10.0 02 Jul 2019, 17:15 UTC

Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.

CVE-2019-7268 nortekcontrol vulnerability CVSS: 10.0 02 Jul 2019, 17:15 UTC

Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.

CVE-2019-7267 nortekcontrol vulnerability CVSS: 7.5 02 Jul 2019, 17:15 UTC

Linear eMerge 50P/5000P devices allow Cookie Path Traversal.

CVE-2019-7266 nortekcontrol vulnerability CVSS: 7.5 02 Jul 2019, 17:15 UTC

Linear eMerge 50P/5000P devices allow Authentication Bypass.

CVE-2019-7265 nortekcontrol vulnerability CVSS: 10.0 02 Jul 2019, 17:15 UTC

Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).

CVE-2019-7264 nortekcontrol vulnerability CVSS: 7.5 02 Jul 2019, 17:15 UTC

Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.

CVE-2019-7263 nortekcontrol vulnerability CVSS: 10.0 02 Jul 2019, 17:15 UTC

Linear eMerge E3-Series devices have a Version Control Failure.

CVE-2019-7271 nortekcontrol vulnerability CVSS: 5.0 01 Jul 2019, 21:15 UTC

Nortek Linear eMerge 50P/5000P devices have Default Credentials.

CVE-2018-5439 nortekcontrol vulnerability CVSS: 10.0 19 Feb 2018, 18:29 UTC

A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.