CVE-2022-31499
RCE in Nortekcontrol Emerge E3 Firmware ≤ 0.32-09c
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2022-31499 is a critical-severity OS Command Injection (CWE-78) vulnerability in Nortekcontrol Emerge E3 Firmware. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 0.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and SI-10 (Information Input Validation) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Nortek Linear eMerge E3-Series devices before version 0.32-08f contain an OS command injection vulnerability tracked as CVE-2022-31499. The flaw resides in the handling of the ReaderNo parameter and stems from an incomplete remediation of the earlier CVE-2019-7256 issue. It carries a CVSS 3.1 base score of 9.8 and is classified under CWE-78.
An unauthenticated attacker with network access can supply crafted input to ReaderNo and execute arbitrary operating-system commands on the affected device, resulting in full compromise of confidentiality, integrity, and availability.
Public references include a detailed proof-of-concept exploit published on Packet Storm and an accompanying technical write-up on GitHub by researcher Omar Hashem, confirming remote unauthenticated command execution is achievable in practice. The EPSS score has reached a peak of 0.9380 with a current value of 0.9325.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-52957
Vulnerability Data
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
- CWE(s)
Related Threats
Likely ATT&CK TechniquesAI
Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Requires validation of the ReaderNo parameter to block crafted OS command payloads before execution.
Enforces authorization checks so unauthenticated network requests cannot invoke device functions that execute OS commands.
Restricts privileges of the web-facing process so even successful injection via ReaderNo yields limited OS access.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
PR.PS-06's SDLC practices directly require secure coding and input handling that blocks command-injection defects, yet the single broad outcome leaves many specific neutralization vectors and verification gaps unaddressed.
Routine patching/maintenance can remediate known command-injection CVEs in dependencies (partial forward) but does nothing to stop developers from introducing improper neutralization in custom code (none reverse).
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing and code review target insecure use of operating-system command interfaces, catching command-injection flaws introduced during development.