S4E just found a medium [ai] private ip disclosure detection scanner
high·Product Based Web Vulnerabilities·Updated May 6, 2024

CVE-2024-0305 Scanner

CVE-2024-0305 Scanner - Remote Code Execution vulnerability in Ncast

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
6
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-0305
7.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Ncastby Guangzhou Yingke Electronic Technology
2017
Updated Aug 22, 2026View on NVD →
Detail

The Ncast Yingshi high-definition intelligent recording and playback system is widely used for audio and video recording and playback. Developed by Ncast Project, it is utilized across various industries for surveillance, security, and multimedia purposes.

The vulnerability detected in Ncast versions 2017 and earlier allows remote attackers to execute arbitrary code on the affected system, posing a significant security risk.

The vulnerability resides in the busiFacade.php endpoint of the Ncast system. Attackers can exploit this by sending a crafted HTTP POST request containing malicious code, typically achieved through JSON input.

Exploitation of this vulnerability can lead to unauthorized execution of arbitrary commands on the target system. Attackers can leverage this to gain control over the system, steal sensitive data, or disrupt normal operations.

By utilizing S4E's comprehensive scanning services, you can proactively identify and mitigate vulnerabilities like the CVE-2024-0305 in Ncast. Stay ahead of potential threats and protect your digital assets effectively by joining our platform today.

 

References:

Solution Advice
  • Apply the latest security patches provided by Ncast Project to mitigate the vulnerability.
  • Implement network-level protections, such as firewalls and intrusion detection systems, to detect and block suspicious traffic.
  • Regularly update and monitor the Ncast system for any signs of unauthorized access or unusual behavior.
  • Restrict access to the busiFacade.php endpoint and enforce strong authentication mechanisms.
  • Educate users and administrators about the risks associated with opening untrusted files or links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-0305 Scanner - Remote Code Execution vulnerability in Ncast S4E