CVE-2021-47728
Severity CVSS v4.0:
CRITICAL
Type:
CWE-78
OS Command Injections
Publication date:
09/12/2025
Last modified:
23/02/2026
Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



