CVE-2025-34022

Public Exploit
Selea Targa IP OCR-ANPR Camera Path Traversal

Description

A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in the “Download Archive in Storage” page fails to properly validate user-supplied input to the file parameter. Unauthenticated remote attackers can exploit this vulnerability to read arbitrary files on the device, including sensitive system files containing cleartext credentials, potentially leading to authentication bypass and exposure of system information.

Category

9.3
CVSS
Severity: Critical
CVSS 4.0 •
EPSS 0.21%
Third-Party Advisory zeroscience.mk Third-Party Advisory packetstorm.news Third-Party Advisory cxsecurity.com Third-Party Advisory exploit-db.com Third-Party Advisory vulncheck.com
Affected: Selea Targa IP OCR-ANPR Camera
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-34022?
CVE-2025-34022 has been scored as a critical severity vulnerability.
How to fix CVE-2025-34022?
To fix CVE-2025-34022, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2025-34022 being actively exploited in the wild?
It is possible that CVE-2025-34022 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-34022?
CVE-2025-34022 affects Selea Targa IP OCR-ANPR Camera.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.