Description
This module exploits a command injection vulnerability in the Linear eMerge E3-Series Access Controller. The Linear eMerge E3 versions `1.00-06` and below are vulnerable to unauthenticated command injection in card_scan_decoder.php via the `No` and `door` HTTP GET parameter. Successful exploitation results in command execution as the `root` user.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/linear/emerge_unauth_rce_cve_2019_7256msf undefined(emerge_unauth_rce_cve_2019_7256) > show actions ...actions...msf undefined(emerge_unauth_rce_cve_2019_7256) > set ACTION < action-name >msf undefined(emerge_unauth_rce_cve_2019_7256) > show options ...show and set options...msf undefined(emerge_unauth_rce_cve_2019_7256) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub