Focus on nortekcontrol vulnerabilities and metrics.
Last updated: 08 Mar 2025, 23:25 UTC
This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with nortekcontrol. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.
For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.
Total nortekcontrol CVEs: 24
Earliest CVE date: 19 Feb 2018, 18:29 UTC
Latest CVE date: 25 Aug 2022, 23:15 UTC
Latest CVE reference: CVE-2022-31798
30-day Count (Rolling): 0
365-day Count (Rolling): 0
Calendar-based Variation
Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.
Month Variation (Calendar): 0%
Year Variation (Calendar): 0%
Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%
Average CVSS: 6.5
Max CVSS: 10.0
Critical CVEs (≥9): 7
Range | Count |
---|---|
0.0-3.9 | 3 |
4.0-6.9 | 9 |
7.0-8.9 | 5 |
9.0-10.0 | 7 |
These are the five CVEs with the highest CVSS scores for nortekcontrol, sorted by severity first and recency.
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
Linear eMerge E3-Series devices allow Privilege Escalation.
Linear eMerge E3-Series devices allow Unrestricted File Upload.
Linear eMerge E3-Series devices allow Command Injections.
Linear eMerge E3-Series devices allow XSS.
Linear eMerge E3-Series devices allow File Inclusion.
Linear eMerge E3-Series devices allow Directory Traversal.
Linear eMerge E3-Series devices have Default Credentials.
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
Linear eMerge E3-Series devices have Hard-coded Credentials.
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
Linear eMerge 50P/5000P devices allow Authentication Bypass.
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.
Linear eMerge E3-Series devices have a Version Control Failure.
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges.