Critical severity9.8NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2021-47728
CVE-2021-47728
Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- Range: Unknown
- cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:*
- cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:*
- cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:*
- cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/49460nvdExploit
- www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utilsnvdThird Party Advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.phpnvdThird Party Advisory
- www.selea.comnvdProduct
News mentions
0No linked articles in our index yet.