CVE-2020-36904
PUBLISHED 12/31/2025 83251b91-4cc7-4094-a5c7-464a1b83ea10
Technical Description
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing admin passwords and executing system commands.
Affected Products
Selea
Selea CarPlateServer (CPS)
4.0.1.6
References
https://www.exploit-db.com/exploits/49452
ExploitDB-49452
https://www.selea.com
Vendor Homepage
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5622.php
Zero Science Lab Disclosure (ZSL-2021-5622)
https://www.vulncheck.com/advisories/selea-carplateserver-remote-program-execution-via-configuration-endpoint
VulnCheck Advisory: Selea CarPlateServer 4.0.1.6 Remote Program Execution via Configuration Endpoint
Impact Analysis
Attack Vector Network
Attack Complexity Low
Privileges Required None