CVE-2022-31798
MEDIUM NUCLEINortekcontrol Emerge E3 Firmware < 0.32-07p - XSS
Title source: ruleDescription
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
Exploits (1)
Nuclei Templates (1)
Nortek Linear eMerge E3-Series - Cross-Site Scripting
MEDIUMVERIFIEDby ritikchaddha
Shodan:
http.title:"eMerge" || http.title:"emerge" || http.title:"linear emerge"
FOFA:
title="emerge" || title="linear emerge"
Scores
CVSS v3
6.1
EPSS
0.8661
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-384
Status
published
Products (1)
nortekcontrol/emerge_e3_firmware
< 0.32-07p
Published
Aug 25, 2022
Tracked Since
Feb 18, 2026