


Perceptive Security
SOC/SIEM Consultancy

Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
Published:
22 December 2025 at 00:00:00
Alert date:
22 December 2025 at 19:02:51
Source:
cisa.gov
Digiever DS-2105 Pro contains a missing authorization vulnerability that could allow attackers to perform command injection attacks via the time_tzsetup.cgi endpoint. This security flaw enables unauthorized users to execute commands on the affected system without proper authentication checks. The vulnerability affects the Digiever DS-2105 Pro network video recorder device and poses a high security risk due to the potential for remote command execution.
Technical details
Mitigation steps:
Affected products:
Digiever DS-2105 Pro
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2023-52163
https://www.digiever.com/tw/support/faq-content.php?FAQ=217
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
