CVE-2021-47728

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_710_inox:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_750:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_805:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_semplice:-:*:*:*:*:*:*:*

Configuration 12 (hide)

OR cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:*

History

23 Feb 2026, 19:00

Type Values Removed Values Added
CPE cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_semplice:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_750:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:*
cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_710_inox:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:*
cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_805:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:*
First Time Selea izero Column Full\/8
Selea targa 750 Firmware
Selea targa 750
Selea
Selea izero Box Full Firmware
Selea targa 504
Selea targa 710 Inox
Selea targa Semplice Firmware
Selea targa 704 Ilb Firmware
Selea izero Column Full\/8 Firmware
Selea targa 704 Tkm
Selea targa 512
Selea targa 512 Firmware
Selea targa 704 Ilb
Selea targa Semplice
Selea izero Box Full
Selea targa 710 Inox Firmware
Selea izero Column Entry\/8
Selea targa 504 Firmware
Selea targa 805
Selea izero Column Entry\/8 Firmware
Selea targa 805 Firmware
Selea carplateserver
Selea targa 704 Tkm Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/zeroscience - () https://github.com/zeroscience - Not Applicable
References () https://www.exploit-db.com/exploits/49460 - () https://www.exploit-db.com/exploits/49460 - Exploit
References () https://www.selea.com - () https://www.selea.com - Product
References () https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utils - () https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utils - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.php - Third Party Advisory

09 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 21:15

Updated : 2026-02-23 19:00


NVD link : CVE-2021-47728

Mitre link : CVE-2021-47728

CVE.ORG link : CVE-2021-47728


JSON object : View

Products Affected

selea

  • targa_704_tkm_firmware
  • targa_750
  • izero_column_entry\/8
  • targa_805_firmware
  • targa_710_inox
  • targa_704_tkm
  • targa_512
  • targa_805
  • targa_semplice
  • targa_704_ilb_firmware
  • targa_704_ilb
  • izero_box_full_firmware
  • targa_512_firmware
  • targa_semplice_firmware
  • izero_column_entry\/8_firmware
  • izero_column_full\/8_firmware
  • izero_box_full
  • targa_504_firmware
  • targa_750_firmware
  • targa_710_inox_firmware
  • carplateserver
  • targa_504
  • izero_column_full\/8
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')