HIGH

CVE-2023-52163

Digiever Ds 2105 Pro Firmware 2025-02-03 CVSS v3.1
CVSS
8.8
KEV

Description

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Summary dbcve.org

Command injection vulnerability in the time_tzsetup.cgi web script on Digiever DS-2105 Pro NVR devices (firmware 3.1.0.71-11). An attacker can inject arbitrary operating system commands through unsanitized input parameters in the time zone setup functionality, potentially achieving remote code execution with the privileges of the web server.

Mitigation

Since the affected product is end-of-life and no longer supported by the vendor, there is no official patch. Organizations should replace unsupported devices with supported models. If immediate replacement is not feasible, network isolation and restrictive access controls should be applied to limit exposure.

Proof of Concept

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

96.92%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE