Aller au contenu

Fiche vulnérabilité

CVE-2021-47728 : faille critique selea izero box full firmware (CVSS 9.8)

Description

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
9 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • selea izero box full firmware
  • selea izero column entry\/8 firmware
  • selea izero column full\/8 firmware
  • selea targa 504 firmware
  • selea targa 512 firmware
  • selea targa 704 ilb firmware
  • selea targa 704 tkm firmware
  • selea targa 710 inox firmware
  • selea targa 750 firmware
  • selea targa 805 firmware
  • selea targa semplice firmware
  • selea carplateserver

Références

Rechercher une autre vulnérabilité dans la base CVE