vendor:
Targa IP OCR-ANPR Camera
by:
LiquidWorm
7.5
CVSS
HIGH
Developer Backdoor Config Overwrite
798
CWE
Product Name: Targa IP OCR-ANPR Camera
Affected Version From: BLD201113005214
Affected Version To: BLD191021180140
Patch Exists: YES
Related CWE: CVE-2020-25862
CPE: h:selea:targa_ip_ocr-anpr_camera
Other Scripts:
N/A
Platforms Tested: None
2020
Selea Targa IP OCR-ANPR Camera – Developer Backdoor Config Overwrite
There is a hard-coded password for a hidden and undocumented /dev.html page that enables the vendor to enable configuration upload / overwrite trought the web interface.
Mitigation:
Upgrade to the latest version of the firmware.