What is Digiever DS-2105 Pro?
Digiever is a Taiwanese manufacturer of network video recorders (NVRs) and IP camera systems for physical security and surveillance deployments. The DS-2105 Pro is a network-attached NVR that receives, records, and manages video feeds from IP cameras over a local network or the internet. NVR devices run embedded Linux firmware with web-based management interfaces and are often internet-accessible — either intentionally (for remote monitoring) or accidentally (due to port forwarding configurations). CCTV and NVR devices are a recurring target for Mirai botnet variants and other IoT malware campaigns: they are always-on, rarely receive firmware updates, run Linux, and provide useful compute and network resources for DDoS infrastructure or proxy traffic.
Overview
CVE-2023-52163 is a missing authorization vulnerability in the Digiever DS-2105 Pro NVR that allows a low-privilege authenticated attacker to execute OS commands via the time_tzsetup.cgi endpoint, which handles timezone configuration. Because authorization checks on this endpoint are absent or insufficient, an attacker with any valid login (including guest or viewer accounts) can invoke the timezone configuration CGI script with injected OS commands. CISA added it to the Known Exploited Vulnerabilities catalog in December 2025, confirming active botnet exploitation.
Affected Versions
| Product | Status |
|---|---|
| Digiever DS-2105 Pro | Affected — apply vendor patch per Digiever advisory |
Technical Details
CWE-862 (Missing Authorization). The DS-2105 Pro's web interface includes time_tzsetup.cgi, a CGI script that processes timezone configuration requests. This endpoint should require administrative authorization to invoke, but authorization enforcement is absent or bypassed. A low-privilege authenticated user can send a crafted HTTP request to time_tzsetup.cgi with OS command characters injected into the parameter values that are passed to the underlying Linux shell.
Command injection via CGI timezone handlers is a well-established pattern in embedded Linux device firmware: timezone settings often invoke OS-level tzdata or timedatectl commands, and insufficient input sanitization in the CGI wrapper allows injecting arbitrary commands alongside legitimate timezone values. Successful exploitation provides OS command execution under the web server process user (typically root on embedded Linux NVRs), enabling backdoor installation, botnet agent deployment, and access to recorded video data.
Discovery
Identified by security researchers and disclosed in February 2025. The late CVE publication date (2025) despite the CVE ID indicating a 2023 vulnerability reflects the delayed CVE assignment timeline common for embedded device vulnerabilities.
Exploitation Context
NVR and CCTV devices from multiple vendors are systematically exploited by Mirai botnet variants that maintain large databases of known CGI vulnerabilities across embedded Linux devices. The KEV addition in December 2025 confirms that CVE-2023-52163 was incorporated into active botnet scanning and exploitation campaigns. Internet-accessible NVRs are identified at scale by botnet operators using Shodan and similar scanning infrastructure, then automatically exploited to deploy botnet agents. Compromised NVRs are used for DDoS attacks and as proxy relay nodes.
Remediation
- Apply the firmware update from Digiever's security advisory for the DS-2105 Pro immediately.
- If a firmware update is not available or the device is end-of-life: remove the device from internet-accessible networks and restrict access to trusted local networks only.
- Disable remote access via port forwarding or direct internet exposure — NVR management and RTSP streams should be accessed via VPN rather than direct internet exposure.
- Check the NVR's active network connections and running processes for evidence of botnet malware (unexpected outbound connections to external IPs, high network utilization without active recording).
- Change all NVR user account passwords — default credentials and weak passwords compound the PR:L exploit risk.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2023-52163 |
| Vendor / Product | Digiever — DS-2105 Pro |
| NVD Published | 2025-02-03 |
| NVD Last Modified | 2025-12-24 |
| CVSS 3.1 Score | 8.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Severity | HIGH |
| CWE | CWE-862 find similar ↗ |
| CISA KEV Added | 2025-12-22 |
| CISA KEV Deadline | 2026-01-12 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2025-02-03 | CVE-2023-52163 published — Digiever DS-2105 Pro missing authorization enabling command injection via time_tzsetup.cgi |
| 2025-12-22 | CISA adds to Known Exploited Vulnerabilities catalog — active botnet exploitation confirmed |
| 2026-01-12 | CISA BOD 22-01 remediation deadline |
References
| Resource | Type |
|---|---|
| Digiever Security Advisory — DS-2105 Pro | Vendor Advisory |
| NVD — CVE-2023-52163 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |