Selea Targa IP Camera Remote Code Execution via Utils
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Selea · Selea Targa IP OCR-ANPR Camerapublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/49460unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.