ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

criticalVulnerability exploited in the wildimportance 60CVE-2023-52163CVE-2023-52164

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-52163
Missing Authorization Enables Command Injection in Digiever DS-2105 Pro NVRs

Digiever DS-2105 Pro network video recorders (firmware version 3.1.0.71-11 is cited in the advisory) expose a time_tzsetup.cgi endpoint that fails to properly enforce authorization (CWE-862), and crafted requests to it trigger operating-system command injection; the CVSS 8.8 score reflects network reachability, low privilege requirements, and no user interaction. Successful exploitation yields command execution on the device with high impact on confidentiality, integrity, and availability — effectively remote code execution, which makes these NVRs attractive targets for IoT botnets such as the RondoDox campaign and the Mirai-variant ShadowV2. Only organizations still running the DS-2105 Pro (or DS-2105 Pro+) are affected, and because the vendor no longer supports the product, unpatched internet-facing units are the primary risk. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-12-22, EPSS puts the 30-day exploitation probability at 96.9%, and ransomware use is currently unknown.

Do: Because the product is end-of-life, check with Digiever for any final firmware update and apply it per vendor instructions; if no patch or mitigation is available, the CISA KEV required action is to discontinue use of the device, and federal agencies must follow BOD 22-01 timelines. In the interim, remove direct internet exposure of the NVR's web interface (restrict via firewall or place behind VPN) and hunt for compromise by looking for suspicious requests to time_tzsetup.cgi and unexpected outbound connections consistent with botnet infection.

8.897% KEV PoC ×3
  • Digiever DS-2105 Pro NVR firmware 3.1.0.71-11 (the version named in the advisory; the product is end-of-life and no longer supported)
  • Digiever DS-2105 Pro+ NVR firmware
moderatelikely on the order of thousands of internet-exposed NVRs (estimated; exact install base unknown)
CVE-2023-52164
access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read.

access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
5.1<1%
Full article240 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 25, 2025Vulnerability / Endpoint Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2023-52163 (CVSS score: 8.8), relates to a case of command injection that allows post-authentication remote code execution.

"Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi," CISA said.

The addition of CVE-2023-52163 to the KEV catalog comes in the multiple reports from Akamai and Fortinet about the exploitation of the flaw by threat actors to deliver botnets like Mirai and ShadowV2.

According to TXOne Research security researcher Ta-Lun Yen, the vulnerability, alongside an arbitrary file read bug (CVE-2023-52164, CVSS score: 5.1), remains unpatched due to the device reaching end-of-life (EoL) status.

Successful exploitation requires an attacker to be logged into the device and perform a crafted request. In the absence of a patch, it's advised that users avoid exposing the device to the internet and change the default username and password.

CISA is also recommending that Federal Civilian Executive Branch (FCEB) agencies apply the necessary mitigations or discontinue use of the product by January 12, 2025, to secure their network from active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/12/cisa-flags-actively-exploited-digiever.html