Command injection vulnerability in Digiever DS-2105 Pro NVR devices allows remote code execution via the time_tzsetup.cgi endpoint. This IoT surveillance device is commonly internet-facing for remote monitoring and is actively exploited in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-02-03
Added to CISA KEV: 2025-12-22 322 DAYS BETWEEN CVE AND KEV
CVE-2023-52163 is a critical security vulnerability affecting specific Digiever network video recorder (NVR) devices. Below is a summary of the known details regarding this vulnerability.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog. Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and ... An official website of the United States government NVD MENU…
Description. Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products ... Patched versions.Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability. Atta…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-52163…