ZeroHour

CVE-2023-52163

KEV PoC ×3moderate

Missing Authorization Enables Command Injection in Digiever DS-2105 Pro NVRs

CISA: Digiever DS-2105 Pro Missing Authorization Vulnerability

CVSS 3.1
8.8 high
EPSS
97%p100
Published
()
KEV added
AI analysis

Digiever DS-2105 Pro network video recorders (firmware version 3.1.0.71-11 is cited in the advisory) expose a time_tzsetup.cgi endpoint that fails to properly enforce authorization (CWE-862), and crafted requests to it trigger operating-system command injection; the CVSS 8.8 score reflects network reachability, low privilege requirements, and no user interaction. Successful exploitation yields command execution on the device with high impact on confidentiality, integrity, and availability — effectively remote code execution, which makes these NVRs attractive targets for IoT botnets such as the RondoDox campaign and the Mirai-variant ShadowV2. Only organizations still running the DS-2105 Pro (or DS-2105 Pro+) are affected, and because the vendor no longer supports the product, unpatched internet-facing units are the primary risk. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-12-22, EPSS puts the 30-day exploitation probability at 96.9%, and ransomware use is currently unknown.

What to do: Because the product is end-of-life, check with Digiever for any final firmware update and apply it per vendor instructions; if no patch or mitigation is available, the CISA KEV required action is to discontinue use of the device, and federal agencies must follow BOD 22-01 timelines. In the interim, remove direct internet exposure of the NVR's web interface (restrict via firewall or place behind VPN) and hunt for compromise by looking for suspicious requests to time_tzsetup.cgi and unexpected outbound connections consistent with botnet infection.

Affected
Digiever DS-2105 Pro NVR firmware3.1.0.71-11 (the version named in the advisory; the product is end-of-life and no longer supported)
Digiever DS-2105 Pro+ NVR firmware
Estimated exposure
moderatelikely on the order of thousands of internet-exposed NVRs (estimated; exact install base unknown) — No public install-base figure exists, but Digiever is a small surveillance vendor and the DS-2105 Pro is an end-of-life product, and internet-wide scans of Digiever devices have historically surfaced only on the order of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CISA Known Exploited Vulnerability
Affected
Digiever DS-2105 Pro
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
digiever
Products
ds-2105 pro firmware, ds-2105 pro\+ firmware
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news