vendor:
Targa IP OCR-ANPR Camera
by:
LiquidWorm
9.8
CVSS
HIGH
Command Injection
78
CWE
Product Name: Targa IP OCR-ANPR Camera
Affected Version From: BLD201113005214
Affected Version To: BLD191021180140
Patch Exists: YES
Related CWE: N/A
CPE: h:selea:targa_ip_ocr-anpr_camera
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
Selea Targa IP OCR-ANPR Camera – ‘addr’ Remote Code Execution (Unauthenticated)
Selea suffers from an authenticated command injection vulnerability. An attacker can send a maliciously crafted HTTP request to the vulnerable device in order to execute arbitrary code.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in system commands.