PT-2022-20657 · Nortek Linear · Emerge E3-Series
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nortek Linear eMerge E3-Series devices versions 0.32-09c and earlier
Description
The issue allows an attacker to obtain admin credentials stored in /test.txt, which can be used to open a building's doors. This occurs even when default credentials have been changed.
Recommendations
For versions 0.32-09c and earlier, remove or restrict access to the /test.txt file to prevent exposure of admin credentials. Consider changing admin credentials and limiting access to the device to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emerge E3-Series