CVE-2021-47728
Selea Targa IP Camera Remote Code Execution via Utils
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 2.3%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
09 Dec 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Selea · Selea Targa IP OCR-ANPR Camerapublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/49460unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →