Executive brief
Selea CarPlateServer is a traffic control and vehicle recognition system used by law enforcement and parking operators to monitor license plates and manage access. The vulnerability allows unauthenticated attackers to bypass authentication, modify server configuration, change administrator passwords, and execute arbitrary Windows programs on affected systems, compromising both confidentiality and operational control of the entire surveillance infrastructure.
Technical details
CarPlateServer contains an authentication bypass vulnerability in the /cps/ endpoint that allows unauthenticated access to the /config_request?ACTION=WRITE endpoint. The vulnerability enables attackers to manipulate the NO_LIST_EXE_PATH configuration parameter to point to arbitrary Windows binaries (e.g., calc.exe, cmd.exe), which are then executed when trigger criteria are met. Additionally, attackers can modify the running configuration to change admin and user passwords. The vulnerability can be exploited via CSRF attacks or by directly navigating to the /cps/ endpoint from a camera IP. Affected versions include 4.0.1.6, 4.013, 3.100, and 3.005; patch availability status is not specified in available advisories.
Affected products
- Selea CarPlateServer 3.005, 3.100, 4.013, 4.0.1.6
Timeline
- 2020-11-08: disclosed
- 2025-12-31: advisory: CVE-2020-36904 published on NVD