Vulnerability Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Selea | Izero Box Full Firmware | - |
| Selea | Izero Box Full | - |
| Selea | Izero Column Entry\/8 Firmware | - |
| Selea | Izero Column Entry\/8 | - |
| Selea | Izero Column Full\/8 Firmware | - |
| Selea | Izero Column Full\/8 | - |
| Selea | Targa 504 Firmware | - |
| Selea | Targa 504 | - |
| Selea | Targa 512 Firmware | - |
| Selea | Targa 512 | - |
| Selea | Targa 704 Ilb Firmware | - |
| Selea | Targa 704 Ilb | - |
| Selea | Targa 704 Tkm Firmware | - |
| Selea | Targa 704 Tkm | - |
| Selea | Targa 710 Inox Firmware | - |
| Selea | Targa 710 Inox | - |
| Selea | Targa 750 Firmware | - |
| Selea | Targa 750 | - |
| Selea | Targa 805 Firmware | - |
| Selea | Targa 805 | - |
Related Weaknesses (CWE)
References
- https://github.com/zeroscienceNot Applicable
- https://www.exploit-db.com/exploits/49460Exploit
- https://www.selea.comProduct
- https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-executionThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.phpThird Party Advisory
FAQ
What is CVE-2021-47728?
CVE-2021-47728 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'add...
How severe is CVE-2021-47728?
CVE-2021-47728 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-47728?
Check the references section above for vendor advisories and patch information. Affected products include: Selea Izero Box Full Firmware, Selea Izero Box Full, Selea Izero Column Entry\/8 Firmware, Selea Izero Column Entry\/8, Selea Izero Column Full\/8 Firmware.