← Volver a CVEs
CVE-2021-47728
CRITICAL9.8
Descripcion
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado12/9/2025
Ultima modificacion2/23/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
selea:carplateserverselea:izero_box_fullselea:izero_box_full_firmwareselea:izero_column_entry\/8selea:izero_column_entry\/8_firmwareselea:izero_column_full\/8selea:izero_column_full\/8_firmwareselea:targa_504selea:targa_504_firmwareselea:targa_512selea:targa_512_firmwareselea:targa_704_ilbselea:targa_704_ilb_firmwareselea:targa_704_tkmselea:targa_704_tkm_firmwareselea:targa_710_inoxselea:targa_710_inox_firmwareselea:targa_750selea:targa_750_firmwareselea:targa_805selea:targa_805_firmwareselea:targa_sempliceselea:targa_semplice_firmware
Debilidades (CWE)
CWE-78
Referencias
https://github.com/zeroscience(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/49460(disclosure@vulncheck.com)
https://www.selea.com(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utils(disclosure@vulncheck.com)
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.php(disclosure@vulncheck.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.