PT-2025-1555 · Digiever · Digiever Ds-2105 Pro
Ta-Lun Yen
·
Published
2025-01-23
·
Updated
2026-01-03
·
CVE-2023-52163
CVSS v3.1
8.8
8.8
High
| Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Digiever DS-2105 Pro versions 3.1.0.71-11
Digiever DS-2105 Pro (affected versions not specified)
Description
The Digiever DS-2105 Pro network video recorder (NVR) has a flaw related to missing authorization, allowing for command injection via the
time tzsetup.cgi endpoint. This allows an attacker, after successful authentication, to execute arbitrary commands on the system. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this issue to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Researchers have linked exploitation attempts to the Mirai and ShadowV2 botnets. The device is reported to be end-of-life and no longer supported by the vendor. The vulnerability has a CVSS score of 8.8 (High).API Endpoints
/time tzsetup.cgiRecommendations
Digiever DS-2105 Pro versions 3.1.0.71-11: Given that the device is end-of-life and unpatched, avoid exposing the NVR to the internet.
Digiever DS-2105 Pro versions 3.1.0.71-11: Change default usernames and passwords to enhance security.
Digiever DS-2105 Pro (affected versions not specified): Isolate or segment the affected NVR/DVR management interfaces.
Digiever DS-2105 Pro (affected versions not specified): Implement least-privilege controls.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-10935
CVE-2023-52163
Affected Products
Digiever Ds-2105 Pro
References · 44
- 🔥 https://fortinet.com/blog/threat-research/shadowv2-casts-a-shadow-over-iot-devices · Exploit
- 🔥 https://akamai.com/blog/security-research/digiever-fix-that-iot-thing · Exploit
- 🔥 https://txone.com/blog/digiever-fixes-sorely-needed · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2023-52163 · Security Note
- https://digiever.com/tw/support/faq-content.php?FAQ=217 · Security Note
- https://bdu.fstec.ru/vul/2025-10935 · Security Note
- https://twitter.com/JamaalChalid/status/2004734106383286706 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1pwvbi0/top_10_trending_cves_27122025 · Reddit Post
- https://twitter.com/ai_tldr1/status/2004690256432693346 · Twitter Post
- https://reddit.com/r/pwnhub/comments/1pvk5br/cisa_warns_of_serious_flaw_in_digiever_nvrs · Reddit Post
- https://twitter.com/ox0ffff/status/2007553166946992557 · Twitter Post
- https://t.me/true_secator/7514 · Telegram Post
- https://twitter.com/BOMvault/status/2004206710932554189 · Twitter Post
- https://t.me/thehackernews/8118 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1pw1sad/top_10_trending_cves_26122025 · Reddit Post