Advisories

Selea Targa IP Camera Remote Code Execution via Utils

Go Back
severity
critical
date
Affecting
  • Model: iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, Targa 704 ILB

  • Firmware: BLD201113005214, BLD201106163745, BLD200304170901, BLD200304170514, BLD200303143345, BLD191118145435, BLD191021180140, BLD191021180140

  • CPS: 4.013(201105), 3.100(200225), 3.005(191206), 3.005(191112)

CWE
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS
10
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.