Vulnerability record · CVE-2023-52163 · published 3 February 2025
CVE-2023-52163: Digiever DS-2105 Pro time_tzsetup.cgi command injection
Digiever · Ds 2105 Pro Firmware
Digiever DS-2105 Pro firmware 3.1.0.71-11 exposes time_tzsetup.cgi to command injection, and the record also maps the issue to CWE-862 missing authorization. The product is end-of-life and no longer supported by the maintainer, so no vendor fix is expected. It matters because the device is remotely reachable and the flaw is listed in CISA KEV with a very high EPSS score.
Description
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score, has public exploit references, and affects an unsupported device with no vendor fix.
What it is
Digiever DS-2105 Pro firmware 3.1.0.71-11 exposes time_tzsetup.cgi to command injection, and the record also maps the issue to CWE-862 missing authorization. The product is end-of-life and no longer supported by the maintainer, so no vendor fix is expected. It matters because the device is remotely reachable and the flaw is listed in CISA KEV with a very high EPSS score.
Impact
An attacker can execute arbitrary commands on the device, giving full compromise of confidentiality, integrity and availability per the CVSS vector. That typically means control of the appliance and any data or network position it holds.
Attack surface
Reached over the network via the time_tzsetup.cgi endpoint; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). The missing authorization weakness suggests the endpoint may be reachable with weak or absent access control, but the record does not state whether unauthenticated access is possible.
Exploitation
CISA added it to KEV with a due date of 2026-01-12, and EPSS gives a 30-day probability of 0.96921 (99.886th percentile). Multiple third-party references are tagged Exploit, indicating public exploit detail exists; no ransomware campaign use is documented.
What to do
- Patch or replace the device: the maintainer no longer supports DS-2105 Pro, so apply any vendor mitigation if one exists or discontinue use per CISA's required action.
- If the device must stay in service, isolate it on a segmented network with no internet exposure and restrict management access to trusted hosts.
- Block or monitor access to time_tzsetup.cgi at the network edge and reverse proxy where possible.
- Enforce strong authentication and least privilege on the device and any adjacent systems it can reach.
- Plan migration to a supported product, since no fix is expected for end-of-life hardware.
Detection
- Monitor web logs and network traffic for requests to time_tzsetup.cgi, especially with shell metacharacters or unexpected parameters.
- Alert on outbound connections or process execution from the device that is inconsistent with normal NVR behavior.
- Hunt for known exploit indicators from the Akamai, TXOne and Fortinet research referenced in the record.
- Review authentication and authorization logs on the device for access to time_tzsetup.cgi by unexpected users or sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-52163 to the Known Exploited Vulnerabilities catalog on 22 December 2025 as "Digiever DS-2105 Pro Missing Authorization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 January 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.akamai.com/blog/security-research/digiever-fix-that-iot-thing | ExploitThird Party Advisory |
| https://www.txone.com/blog/digiever-fixes-sorely-needed/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-52163 | US Government Resource |
| https://www.fortinet.com/blog/threat-research/shadowv2-casts-a-shadow-over-iot-devices | ExploitThird Party Advisory |
Track CVE-2023-52163 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-52163), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.