CVE-2021-47729

Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_710_inox:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_750:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_805:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_semplice:-:*:*:*:*:*:*:*

Configuration 12 (hide)

OR cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:*

History

23 Feb 2026, 19:00

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49454 - () https://www.exploit-db.com/exploits/49454 - Exploit
References () https://www.selea.com - () https://www.selea.com - Product
References () https://www.selea.com/product/ - () https://www.selea.com/product/ - Product
References () https://www.vulncheck.com/advisories/selea-targa-ip-camera-stored-cross-site-scripting-via-files-list - () https://www.vulncheck.com/advisories/selea-targa-ip-camera-stored-cross-site-scripting-via-files-list - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5614.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5614.php - Third Party Advisory
CPE cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_semplice:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_750:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:*
cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_710_inox:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:*
cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:selea:targa_805:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:*
cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:*
cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:*
First Time Selea izero Column Full\/8
Selea targa 750 Firmware
Selea targa 750
Selea
Selea izero Box Full Firmware
Selea targa 504
Selea targa 710 Inox
Selea targa Semplice Firmware
Selea targa 704 Ilb Firmware
Selea izero Column Full\/8 Firmware
Selea targa 704 Tkm
Selea targa 512
Selea targa 512 Firmware
Selea targa 704 Ilb
Selea targa Semplice
Selea izero Box Full
Selea targa 710 Inox Firmware
Selea izero Column Entry\/8
Selea targa 504 Firmware
Selea targa 805
Selea izero Column Entry\/8 Firmware
Selea targa 805 Firmware
Selea carplateserver
Selea targa 704 Tkm Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

09 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 21:15

Updated : 2026-02-23 19:00


NVD link : CVE-2021-47729

Mitre link : CVE-2021-47729

CVE.ORG link : CVE-2021-47729


JSON object : View

Products Affected

selea

  • targa_704_tkm_firmware
  • targa_750
  • izero_column_entry\/8
  • targa_805_firmware
  • targa_710_inox
  • targa_704_tkm
  • targa_512
  • targa_805
  • targa_semplice
  • targa_704_ilb_firmware
  • targa_704_ilb
  • izero_box_full_firmware
  • targa_512_firmware
  • targa_semplice_firmware
  • izero_column_entry\/8_firmware
  • izero_column_full\/8_firmware
  • izero_box_full
  • targa_504_firmware
  • targa_750_firmware
  • targa_710_inox_firmware
  • carplateserver
  • targa_504
  • izero_column_full\/8
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')