LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-52163: Digiever DS-2105 Pro Missing Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 22, 2025
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 12, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-52163 to its Known Exploited Vulnerabilities catalog on Dec 22, 2025, with a federal patch deadline of Jan 12, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

The vulnerability CVE-2023-52163 affects the Digiever DS-2105 Pro and involves a missing authorization weakness. This condition could allow an attacker to perform command injection through the time_tzsetup.cgi interface without proper access controls. Such issues matter for organizations that rely on these devices for surveillance or recording functions, as unauthorized command execution can lead to device compromise.

How it works

The weakness is identified as CWE-862, missing authorization. In this class of flaw, the application fails to enforce permission checks before processing requests to specific endpoints.

An attacker can submit crafted input to time_tzsetup.cgi and cause command injection because the code path does not verify that the caller holds the required privileges.

Am I affected? How to find it in your systems

Digiever DS-2105 Pro devices typically operate as network-attached video recorders or surveillance appliances. Inventory all instances by querying network management systems, DHCP logs, or asset databases for the product name.

How to remediate

Apply mitigations per the vendor instructions referenced in the advisory. Where the product integrates with cloud services, follow applicable BOD 22-01 guidance.

If you can't patch immediately

Apply mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services. If mitigations cannot be implemented, discontinue use of the product.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDigiever · DS-2105 Pro
WeaknessCWE-862
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedFeb 3, 2025
Added to CISA KEVDec 22, 2025
Federal patch deadlineJan 12, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities