Record summary

CVE-2022-38627 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 13, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 10, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

linear_emerge_e3_access_control_firmware

Browse niceforyou / linear_emerge_e3_access_control_firmware
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALNortek Linear eMerge E3-Series - SQL InjectionCVSS 9.8

Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

Impact

Unauthenticated attackers can exploit SQL injection in the idt parameter to extract sensitive access control data including badge information, user credentials, and building security configurations from the eMerge access control system.

Remediation

Update Nortek Linear eMerge E3-Series firmware to a patched version that uses parameterized queries and properly sanitizes the idt parameter.

WeaknessesCWE-89
Authorsdaffainfo, omarhashem666
Template tagscvecve2022emergenorteklinearsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:nortekcontrol:emerge_e3_firmware:*:*:*:*:*:*:*:*
Shodan: http.title:"Linear eMerge"

Source: ProjectDiscovery

References

3