Vulnerability record · CVE-2024-0305 · published 8 January 2024
CVE-2024-0305: Ncast Guest Login IPSetup.php information disclosure
Ncast Project · Ncast
Ncast (Guangzhou Yingke Electronic Technology) up to 2017 exposes information through the /manage/IPSetup.php file in the Guest Login component. The flaw is an information exposure issue (CWE-200) reachable remotely without authentication, and a public exploit has been disclosed. Because the affected versions and exact data exposed are not specified, defenders must treat any Ncast deployment as potentially at risk.
Description
A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote information disclosure with a public exploit and very high EPSS score, though no KEV listing or confirmed in-the-wild use is documented.
What it is
Ncast (Guangzhou Yingke Electronic Technology) up to 2017 exposes information through the /manage/IPSetup.php file in the Guest Login component. The flaw is an information exposure issue (CWE-200) reachable remotely without authentication, and a public exploit has been disclosed. Because the affected versions and exact data exposed are not specified, defenders must treat any Ncast deployment as potentially at risk.
Impact
An unauthenticated remote attacker can read sensitive information exposed by IPSetup.php, which may include configuration or network details useful for follow-on attacks. The record does not state exactly what data is leaked, so the full confidentiality impact is uncertain.
Attack surface
Reached over the network via HTTP requests to /manage/IPSetup.php; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required. The Guest Login component suggests the endpoint is accessible to unauthenticated visitors.
Exploitation
A public exploit is referenced (GitHub logic.md tagged Exploit), and EPSS is 0.669 (99.3rd percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Apply the vendor patch or update for Ncast if available; if no patch exists, isolate or retire affected devices.
- Restrict network access to /manage/IPSetup.php and the management interface to trusted networks or VPN only.
- Disable or block the Guest Login component if it is not required.
- Monitor vendor advisories for updated affected-version information, since the record does not specify versions.
- Place affected systems behind a reverse proxy or WAF rule that blocks direct access to /manage/IPSetup.php.
Detection
- Search web access logs for requests to /manage/IPSetup.php, especially from untrusted or external source IPs.
- Alert on unauthenticated access to /manage/ paths on Ncast devices.
- Monitor for anomalous outbound traffic or configuration scraping following IPSetup.php requests.
- Review Ncast device logs for repeated or automated requests to the Guest Login component.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/2267787739/cve/blob/main/logic.md | Exploit |
| https://vuldb.com/?ctiid.249872 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.249872 | Permissions RequiredThird Party Advisory |
| https://github.com/2267787739/cve/blob/main/logic.md | Exploit |
| https://vuldb.com/?ctiid.249872 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.249872 | Permissions RequiredThird Party Advisory |
Track CVE-2024-0305 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-0305), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.