CVE-2024-0305 is an information disclosure vulnerability affecting Guangzhou Yingke Electronic Technology Ncast devices up to 2017, specifically within the /manage/IPSetup.php component related to Guest Login functionality. This vulnerability carries a high CVSS score of 7.5, indicating a critical risk due to its network-based attack vector, low attack complexity, and high potential for information compromise without requiring user interaction. While not listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 99/100 suggest a significant likelihood of exploitation. Public exploit details are available, including a Nuclei template for Remote Command Execution, and it has garnered community discussion and media coverage, indicating active awareness and potential for real-world attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2007, <= 2017CPE matchmatch criteria | cpe:2.3:a:ncast_project:ncast:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.