Junglewise Threat Intelligence

CVE-2020-36904: Selea CarPlateServer authentication bypass and remote code execution

CVE-2020-36904 · Severity: high · CVSS 7.5 · Published 2025-12-31

Executive brief

Selea CarPlateServer is a traffic control and vehicle recognition system used by law enforcement and parking operators to monitor license plates and manage access. The vulnerability allows unauthenticated attackers to bypass authentication, modify server configuration, change administrator passwords, and execute arbitrary Windows programs on affected systems, compromising both confidentiality and operational control of the entire surveillance infrastructure.

Technical details

CarPlateServer contains an authentication bypass vulnerability in the /cps/ endpoint that allows unauthenticated access to the /config_request?ACTION=WRITE endpoint. The vulnerability enables attackers to manipulate the NO_LIST_EXE_PATH configuration parameter to point to arbitrary Windows binaries (e.g., calc.exe, cmd.exe), which are then executed when trigger criteria are met. Additionally, attackers can modify the running configuration to change admin and user passwords. The vulnerability can be exploited via CSRF attacks or by directly navigating to the /cps/ endpoint from a camera IP. Affected versions include 4.0.1.6, 4.013, 3.100, and 3.005; patch availability status is not specified in available advisories.

Affected products

  • Selea CarPlateServer 3.005, 3.100, 4.013, 4.0.1.6

Timeline

  • 2020-11-08: disclosed
  • 2025-12-31: advisory: CVE-2020-36904 published on NVD

References

Related threats