CVE-2025-34021
Last modified
CVE-2025-34021 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The application fails to validate user-supplied input in JSON POST parameters such as ipnotify_address and url, which are used by internal mechanisms to perform image fetch and DNS lookups. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The application fails to validate user-supplied input in JSON POST parameters such as ipnotify_address and url, which are used by internal mechanisms to perform image fetch and DNS lookups. This allows remote unauthenticated attackers to induce the system to make arbitrary HTTP requests to internal or external systems, potentially bypassing firewall policies or conducting internal service enumeration. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-34021?
How severe is CVE-2025-34021?
How do I fix CVE-2025-34021?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3397A vulnerability classified as problematic has been found in …6.1
- CVE-2025-3398A vulnerability classified as critical was found in lenve VB…9.8
- CVE-2025-3399A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-3400A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-3401A vulnerability has been found in ESAFENET CDG 5.6.3.154.205…9.8
- CVE-2025-3402A vulnerability was found in Seeyon Zhiyuan Interconnect FE …7.5
- CVE-2025-34022A path traversal vulnerability exists in multiple models of …9.3
- CVE-2025-34023A path traversal vulnerability exists in the Karel IP1211 IP…8.5
- CVE-2025-34024An OS command injection vulnerability exists in the Edimax E…8.8
- CVE-2025-34025The Versa Concerto SD-WAN orchestration platform is vulnerab…8.6
- CVE-2025-34026The Versa Concerto SD-WAN orchestration platform is vulnerab…7.5
- CVE-2025-34027The Versa Concerto SD-WAN orchestration platform is vulnerab…10
Are you affected by CVE-2025-34021?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
