CVE-2020-36904

PUBLISHED
12/31/2025 83251b91-4cc7-4094-a5c7-464a1b83ea10

Technical Description

Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing admin passwords and executing system commands.

Affected Products

Selea
Selea CarPlateServer (CPS)
4.0.1.6

References

Impact Analysis

Attack Vector Network
Attack Complexity Low
Privileges Required None