S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-27718 Scanner

Targets the login endpoint's username parameter, allowing attackers to extract database credentials and session tokens.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-27718
7.8
CVSShigh
Requires local system access · low-privilege account sufficient.

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

Attack Vector
Local
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
management_platformby byzronetwork
S200
Updated Aug 22, 2026View on NVD →
Detail

The Smart s200 Management Platform by Baizhuo Network is a comprehensive network management solution used by enterprises to monitor, configure, and automate network devices. IT administrators rely on it for real-time traffic analysis, device health checks, and centralized control, making it a backbone for organizational network operations. Its web-based interface provides dashboards and reporting tools that simplify complex network tasks.

CVE-2024-27718 is a SQL injection vulnerability that arises when user-supplied input is improperly sanitized before being used in database queries. This flaw occurs due to insufficient validation of input fields, allowing attackers to inject malicious SQL commands. The vulnerability is particularly dangerous because it can be exploited remotely without authentication, increasing its risk profile.

The vulnerable endpoint is the login page at /login.php, specifically the 'username' parameter. An attacker can submit crafted SQL payloads in this field to manipulate the backend query, bypass authentication, or extract sensitive data. The injection point is directly concatenated into a SELECT statement, enabling time-based or error-based exploitation techniques.

Successful exploitation can lead to unauthorized access to the management platform, exposure of stored credentials, device configurations, and network topology data. Attackers could escalate privileges, modify device settings, or disrupt network operations. In worst-case scenarios, this could result in full network compromise, data breaches, and significant operational downtime.

Solution Advice
  • Upgrade the Smart s200 Management Platform to the latest patched version provided by Baizhuo Network.
  • Implement strict input validation and sanitization for all user-supplied data, especially the username parameter.
  • Use parameterized queries or prepared statements for all database interactions to prevent SQL injection.
  • Apply a Web Application Firewall (WAF) with rules to block common SQL injection patterns.
  • Conduct regular security audits and penetration testing focusing on authentication endpoints.
  • Enforce least privilege database access for the application user to limit potential damage.
  • Monitor logs for suspicious login attempts or unusual database query patterns.
  • Educate developers on secure coding practices to avoid similar vulnerabilities in future updates.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-27718 SQLi Scanner | S4E Free Check S4E