CVE-2023-52163
Digiever DS-2105 Pro Missing Authorization Vulnerability
Record summary
CVE-2023-52163 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template. CISA lists CVE-2023-52163 in KEV.
Description
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Dec 22, 2025 · CISA
- VulnCheck KEV
- Listed · Dec 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DS-2105 ProBrowse Digiever / DS-2105 Pro | CISA | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHDigiever DS-2105 Pro - Command Injection
Digiever DS-2105 Pro 3.1.0.71-11 contains a command injection caused by unsanitized input in time_tzsetup.cgi, letting attackers execute arbitrary commands remotely, exploit requires no authentication.
Impact
Remote attackers can execute arbitrary commands on the device, potentially leading to full device compromise.
Remediation
Update to a supported version or contact the vendor for security patches.
Source: ProjectDiscovery