CVE-2022-38627
niceforyou linear_emerge_e3_access_control_firmware Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2022-38627 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 13, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
linear_emerge_e3_access_control_firmwareBrowse niceforyou / linear_emerge_e3_access_control_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALNortek Linear eMerge E3-Series - SQL InjectionCVSS 9.8
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
Impact
Unauthenticated attackers can exploit SQL injection in the idt parameter to extract sensitive access control data including badge information, user credentials, and building security configurations from the eMerge access control system.
Remediation
Update Nortek Linear eMerge E3-Series firmware to a patched version that uses parameterized queries and properly sanitizes the idt parameter.
Source: ProjectDiscovery