CVE-2021-47728
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 2.62% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- selea/izero box full firmware · selea/izero column entry\/8 firmware · selea/izero column full\/8 firmware · selea/targa 504 firmware · selea/targa 512 firmware · selea/targa 704 ilb firmware · selea/targa 704 tkm firmware · selea/targa 710 inox firmware · selea/targa 750 firmware · selea/targa 805 firmware · selea/targa semplice firmware · selea/carplateserver
- Source
- disclosure@vulncheck.com
References
- https://github.com/zeroscienceNot Applicable
- https://www.exploit-db.com/exploits/49460Exploit
- https://www.selea.comProduct
- https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utilsThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.phpThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.