Latest
Subscribe
Advertisement

Incident

Unpatched OS command injection in Nice Linear eMerge E3 controllers

CVE ID
CVE-2024-9441
Severity
Critical
CVSS
9.80
Source URL
nvd.nist.gov
Vendor notified at
2025-04-24 00:00:00

The forgot-password login_id parameter in Linear eMerge E3-series access controllers (through 1.00-07) allows unauthenticated OS command injection. Public proof-of-concept exploits circulate; the vendor has advised network segmentation rather than shipping a patch.

Source: nvd.nist.gov

The vendor was notified before publication and offered a response under our right-of-reply policy; none was given. Policy