Junglewise Threat Intelligence

CVE-2023-52163: Digiever DS-2105 Pro command injection in time_tzsetup.cgi

CVE-2023-52163 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-12-22

Executive brief

Digiever DS-2105 Pro series network video recorders (NVRs) contain a security flaw that allows unauthorized users to execute commands on the device. This equipment is used for managing and recording surveillance video, and an exploit could allow an attacker to take full control of the system, potentially accessing video feeds or using the device as a foothold in the corporate network. This vulnerability is currently being exploited in the wild, and because the product is no longer supported by the manufacturer, users are advised to discontinue its use.

Technical details

A missing authorization vulnerability (CWE-862) exists in the time_tzsetup.cgi component of Digiever DS-2105 Pro and Pro+ NVR devices running firmware version 3.1.0.71-11. An attacker with low-privileged network access can exploit this flaw to perform command injection, leading to full system compromise. The vulnerability is confirmed to be exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. As the vendor no longer supports this product, no official patch is available, and mitigation typically requires decommissioning the affected hardware.

Affected products

  • Digiever DS-2105 Pro firmware 3.1.0.71-11
  • Digiever DS-2105 Pro+ firmware 3.1.0.71-11

Timeline

  • 2025-02-03: disclosed: Initial CVE publication
  • 2025-12-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-12-22: advisory: NVD and CISA-ADP updates published