CVE-2021-47728 Details
Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
A command injection vulnerability has been identified in the Selea Targa IP OCR-ANPR Camera. This vulnerability allows remote attackers to execute arbitrary shell commands on the device. The issue arises in the 'utils.php' file, where the 'addr' and 'port' parameters can be exploited to inject commands. The vulnerability takes advantage of local file inclusion techniques to gain access as the 'www-data' user.
Users are advised to update to the latest firmware version, as the vendor has released patches for this vulnerability. Instructions for updating can be found on the Selea website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zeroscience | [email protected] | Not Applicable |
| https://www.exploit-db.com/exploits/49460 | [email protected] | Exploit |
| https://www.selea.com | [email protected] | Product |
| https://www.vulncheck.com/advisories/selea-targa-ip-camera-remote-code-execution-via-utils | [email protected] | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5620.php | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| selea izero box full firmware | All versions |
CPE
Remediation
| |
| selea izero box full | All versions |
CPE
Remediation
| |
| selea izero column entry/8 firmware | All versions |
CPE
Remediation
| |
| selea izero column entry/8 | All versions |
CPE
Remediation
| |
| selea izero column full/8 firmware | All versions |
CPE
Remediation
| |
| selea izero column full/8 | All versions |
CPE
Remediation
| |
| selea targa 504 firmware | All versions |
CPE
Remediation
| |
| selea targa 504 | All versions |
CPE
Remediation
| |
| selea targa 512 firmware | All versions |
CPE
Remediation
| |
| selea targa 512 | All versions |
CPE
Remediation
| |
| selea targa 704 ilb firmware | All versions |
CPE
Remediation
| |
| selea targa 704 ilb | All versions |
CPE
Remediation
| |
| selea targa 704 tkm firmware | All versions |
CPE
Remediation
| |
| selea targa 704 tkm | All versions |
CPE
Remediation
| |
| selea targa 710 inox firmware | All versions |
CPE
Remediation
| |
| selea targa 710 inox | All versions |
CPE
Remediation
| |
| selea targa 750 firmware | All versions |
CPE
Remediation
| |
| selea targa 750 | All versions |
CPE
Remediation
| |
| selea targa 805 firmware | All versions |
CPE
Remediation
| |
| selea targa 805 | All versions |
CPE
Remediation
| |
| selea targa semplice firmware | All versions |
CPE
Remediation
| |
| selea targa semplice | All versions |
CPE
Remediation
| |
| selea carplateserver | 3.005(191112) 3.005(191206) 3.100(200225) 4.013(201105) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | Initial Analysis | [email protected] |
| Dec 9, 2025 | New CVE Received | [email protected] |