CVE-2023-52163 is a critical command injection vulnerability affecting Digiever DS-2105 Pro devices, specifically within the time_tzsetup.cgi component. This flaw allows authenticated attackers to execute arbitrary commands, leading to full compromise of the device. With a CVSS score of 8.8 (High), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, notably by the Mirai/ShadowV2 botnets, and despite the lack of official patches for these end-of-life products, it has garnered substantial community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.0.71-11CPE matchmatch criteria | cpe:2.3:o:digiever:ds-2105_pro_firmware:3.1.0.71-11:*:*:*:*:*:*:* | ||
3.1.0.71-11CPE matchmatch criteria | cpe:2.3:o:digiever:ds-2105_pro\+_firmware:3.1.0.71-11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.