Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
References
| Link | Resource |
|---|---|
| https://github.com/zeroscience | Not Applicable |
| https://www.exploit-db.com/exploits/49460 | Exploit |
| https://www.selea.com | Product |
| https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utils | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.php | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
|
History
23 Feb 2026, 19:00
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:* cpe:2.3:h:selea:targa_semplice:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:* cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_750:-:*:*:*:*:*:*:* cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:* cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_710_inox:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:* cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_805:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:* cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:* |
|
| First Time |
Selea izero Column Full\/8
Selea targa 750 Firmware Selea targa 750 Selea Selea izero Box Full Firmware Selea targa 504 Selea targa 710 Inox Selea targa Semplice Firmware Selea targa 704 Ilb Firmware Selea izero Column Full\/8 Firmware Selea targa 704 Tkm Selea targa 512 Selea targa 512 Firmware Selea targa 704 Ilb Selea targa Semplice Selea izero Box Full Selea targa 710 Inox Firmware Selea izero Column Entry\/8 Selea targa 504 Firmware Selea targa 805 Selea izero Column Entry\/8 Firmware Selea targa 805 Firmware Selea carplateserver Selea targa 704 Tkm Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/zeroscience - Not Applicable | |
| References | () https://www.exploit-db.com/exploits/49460 - Exploit | |
| References | () https://www.selea.com - Product | |
| References | () https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utils - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.php - Third Party Advisory |
09 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 21:15
Updated : 2026-02-23 19:00
NVD link : CVE-2021-47728
Mitre link : CVE-2021-47728
CVE.ORG link : CVE-2021-47728
JSON object : View
Products Affected
selea
- targa_704_tkm_firmware
- targa_750
- izero_column_entry\/8
- targa_805_firmware
- targa_710_inox
- targa_704_tkm
- targa_512
- targa_805
- targa_semplice
- targa_704_ilb_firmware
- targa_704_ilb
- izero_box_full_firmware
- targa_512_firmware
- targa_semplice_firmware
- izero_column_entry\/8_firmware
- izero_column_full\/8_firmware
- izero_box_full
- targa_504_firmware
- targa_750_firmware
- targa_710_inox_firmware
- carplateserver
- targa_504
- izero_column_full\/8
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
