« Volver al listado

CVE-2025-34022

Estado: AplazadaCrítica (9.3)—

A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in the “Download Archive in Storage” page fails to properly validate user-supplied input to the file parameter. Unauthenticated remote attackers can exploit this vulnerability to read arbitrary files on the device, including sensitive system files containing cleartext credentials, potentially leading to authentication bypass and exposure of system information. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de path traversal (CWE-22) en servicio web sin autenticación (AV:N/PR:N/UI:N). Permite lectura de archivos arbitrarios incluyendo credenciales en texto plano.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (10)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-34022",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-34022",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-23T20:36:01.210675Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 9.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "HIGH",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "HIGH",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "vendor": "Selea",
          "modules": [
            "Web Management Interface (get_file.php download handler)"
          ],
          "product": "Targa IP OCR-ANPR Camera",
          "versions": [
            {
              "status": "affected",
              "version": "BLD201113005214",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "BLD201106163745",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "BLD200304170901",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "BLD200304170514",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "BLD200303143345",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "BLD191118145435",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "BLD191021180140",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "CPS 4.013(201105)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "CPS 3.100(200225)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "CPS 3.005(191206)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "CPS 3.005(191112)",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-06-20T19:15:36.720",
  "references": [
    {
      "url": "https://cxsecurity.com/issue/WLB-2021010165",
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://packetstorm.news/files/id/161057",
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://vulncheck.com/advisories/selea-targa-ip-camera-path-traversal",
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://www.exploit-db.com/exploits/49456",
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://www.selea.com",
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5616.php",
      "source": "disclosure@vulncheck.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in the “Download Archive in Storage” page fails to properly validate user-supplied input to the file parameter. Unauthenticated remote attackers can exploit this vulnerability to read arbitrary files on the device, including sensitive system files containing cleartext credentials, potentially leading to authentication bypass and exposure of system information. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de path traversal en varios modelos Selea Targa IP OCR-ANPR cameras, como iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750 y Targa 704 ILB. El script /common/get_file.php de la página \"Descargar archivo en almacenamiento\" no valida correctamente la entrada del usuario en el parámetro \"file\". Atacantes remotos no autenticados pueden explotar esta vulnerabilidad para leer archivos arbitrarios en el dispositivo, incluyendo archivos confidenciales del sistema que contienen credenciales en texto plano, lo que podría provocar la omisión de la autenticación y la exposición de la información del sistema. "
    }
  ],
  "lastModified": "2026-06-17T09:13:19.373",
  "sourceIdentifier": "disclosure@vulncheck.com"
}