CVE-2024-9441: Linear eMerge E3-Series

Critical severity, CVSS 9.8. EPSS: 53.5% chance of exploitation in the next 30 days.

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

Affected products

  • Linear eMerge E3-Series: up to and including 1.00-07
  • Nortekcontrol eMerge e3 Firmware: up to and including 1.00-07

Published 2024-10-02. Last modified 2026-06-17.