PT-2022-20657 · Nortek Linear · Emerge E3-Series

·

CVE-2022-31269

·

Published

2022-08-25

·

Updated

2022-09-02

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nortek Linear eMerge E3-Series devices versions 0.32-09c and earlier
Description The issue allows an attacker to obtain admin credentials stored in /test.txt, which can be used to open a building's doors. This occurs even when default credentials have been changed.
Recommendations For versions 0.32-09c and earlier, remove or restrict access to the /test.txt file to prevent exposure of admin credentials. Consider changing admin credentials and limiting access to the device to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31269

Affected Products

Emerge E3-Series