CVE-2023-52163

9.5 CISA KEV

Digiever · DS-2105 Pro

Digiever DS-2105 Pro devices are vulnerable to command injection via the time_tzsetup.cgi endpoint, allowing authenticated attackers to execute arbitrary commands.

Executive summary

A critical command injection vulnerability in Digiever DS-2105 Pro devices is being actively exploited in the wild, posing a severe risk of unauthorized remote code execution.

Vulnerability

The device contains a command injection flaw within the time_tzsetup.cgi script. This vulnerability allows an authenticated attacker to inject and execute arbitrary system commands on the underlying operating system.

Business impact

With a CVSS score of 9.5, this vulnerability represents a critical security risk. Successful exploitation grants an attacker the ability to execute commands with high privileges, potentially leading to total system compromise, data exfiltration, or the integration of the device into malicious botnets. As the product is end-of-life and unsupported, these devices remain permanently exposed to ongoing threats.

Remediation

Immediate Action: Because the vendor no longer supports this device and no official patches are available, the only effective remediation is to disconnect the device from the network or replace it with a supported alternative.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at the time_tzsetup.cgi endpoint and watch for unusual outbound traffic patterns characteristic of botnet activity.

Compensating Controls: If the device must remain online, place it behind a strict firewall that restricts access to the management interface to known, trusted management IP addresses only.

Exploitation status

Public Exploit Available: Yes — a Nuclei detection template exists.

Analyst recommendation

Given that the affected software is end-of-life and no patches will be issued, the risk to the organization is extreme. Administrators should treat these devices as inherently untrusted and prioritize their immediate removal from the production environment to prevent further compromise.

Sources