CVE-2023-52163: Digiever DS-2105 Pro Missing Authorization Vulnerability
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
How it works
The weakness is identified as CWE-862, missing authorization. In this class of flaw, the application fails to enforce permission checks before processing requests to specific endpoints.
An attacker can submit crafted input to time_tzsetup.cgi and cause command injection because the code path does not verify that the caller holds the required privileges.
Am I affected? How to find it in your systems
Digiever DS-2105 Pro devices typically operate as network-attached video recorders or surveillance appliances. Inventory all instances by querying network management systems, DHCP logs, or asset databases for the product name.
- Confirm the exact firmware and configuration details against the vendor advisory, as only specific builds may contain the vulnerable code path.
- Review web server access logs for unexpected requests to time_tzsetup.cgi, noting any parameters that deviate from normal administrative use.
- Examine authentication and authorization event logs on the device or any connected management consoles for missing or bypassed checks.
How to remediate
Apply mitigations per the vendor instructions referenced in the advisory. Where the product integrates with cloud services, follow applicable BOD 22-01 guidance.
- Disable or restrict access to the affected CGI endpoint if the vendor advisory identifies that option.
- Enforce network-level controls that limit which hosts can reach the device management interface.
- Reassess device placement to ensure it resides only on segmented networks with strict access policies.
If you can't patch immediately
Apply mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services. If mitigations cannot be implemented, discontinue use of the product.
- Place the device behind a network filter that blocks or inspects traffic to time_tzsetup.cgi.
- Monitor for anomalous outbound connections or process execution on the host if such telemetry is available.
- Document the exposure window and schedule replacement or decommissioning.
If your data may have been exposed
Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H