Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage.
Problem types
CWE-306: Missing Authentication for Critical Function
Product status
Model: iZero
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/49459 (ExploitDB-49459)
www.selea.com (Selea s.r.l. Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5619.php (Zero Science Lab Disclosure (ZSL-2021-5619))
github.com/Mbed-TLS/mbedtls (Mbed TLS GitHub Repository)
www.vulncheck.com/...amera-unauthenticated-stream-disclosure (VulnCheck Advisory: Selea Targa IP Camera Unauthenticated Stream Disclosure)