CVE-2021-47728 PUBLISHED

Selea Targa IP Camera Remote Code Execution via Utils

Assigner: VulnCheck
Reserved: 07.12.2025 Published: 09.12.2025 Updated: 12.12.2025

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Selea
Product Selea Targa IP OCR-ANPR Camera
Versions Default: unaffected
  • Version Unknown is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE