← All CVEs

CVE-2021-47728

critical · 9.3

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.

9.3
CVSS
2.6%
EPSS (exploit prob.)
85th
EPSS percentile
2025-12-09
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
seleaizero_box_full_firmwareall versions
seleaizero_box_fullall versions
seleaizero_column_entry/8_firmwareall versions
seleaizero_column_entry/8all versions
seleaizero_column_full/8_firmwareall versions
seleaizero_column_full/8all versions
seleatarga_504_firmwareall versions
seleatarga_504all versions
seleatarga_512_firmwareall versions
seleatarga_512all versions
seleatarga_704_ilb_firmwareall versions
seleatarga_704_ilball versions
seleatarga_704_tkm_firmwareall versions
seleatarga_704_tkmall versions
seleatarga_710_inox_firmwareall versions
seleatarga_710_inoxall versions
seleatarga_750_firmwareall versions
seleatarga_750all versions
seleatarga_805_firmwareall versions
seleatarga_805all versions
seleatarga_semplice_firmwareall versions
seleatarga_sempliceall versions
seleacarplateserver3.005(191112)
seleacarplateserver3.005(191206)
seleacarplateserver3.100(200225)
seleacarplateserver4.013(201105)

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-47728