CVE-2020-36904: Selea Carplateserver Cps
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing admin passwords and executing system commands.
Affected products
- Selea Selea Carplateserver Cps: version 4.0.1.6 only
Published 2025-12-31. Last modified 2026-09-23.