CVE-2023-52163
Description
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Summary dbcve.org
Command injection vulnerability in the time_tzsetup.cgi web script on Digiever DS-2105 Pro NVR devices (firmware 3.1.0.71-11). An attacker can inject arbitrary operating system commands through unsanitized input parameters in the time zone setup functionality, potentially achieving remote code execution with the privileges of the web server.
Mitigation
Since the affected product is end-of-life and no longer supported by the vendor, there is no official patch. Organizations should replace unsupported devices with supported models. If immediate replacement is not feasible, network isolation and restrictive access controls should be applied to limit exposure.