CVE-2023-52163Active Exploitation(digiever / ds-2105_pro)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for digiever ds-2105_pro systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-01-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ds-2105_pro
  • ds-2105_pro\+
  • ds-2105_pro\+_firmware
  • ds-2105_pro_firmware

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ds-2105_prods-2105_pro\+ds-2105_pro\+_firmwareds-2105_pro_firmware

2 versions affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-11: 1Technical Details · 2026-04-11: 104-0904-11
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2023-52163 Exploit in the wild confirmed for CVE-2023-52163 (CVSS 8.8). Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post reports that CVE-2023-52163 is currently being exploited in the wild, highlighting a missing authorization flaw on Digiever DS-2105 Pro and providing a link to further alerts.

    0000094
    5.6K followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-52163 Digiever DS-2105 Pro Missing Authorizat @CISACyber https://www.rfr.bz/t2ef896

    Post summary

    CISA added CVE-2023-52163 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation, but no PoC, patch, or detailed technical information is provided.

    0000038
    1.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWdigieverds-2105_pro---
HWdigieverds-2105_pro\+---
OSdigieverds-2105_pro\+_firmware3.1.0.71-11--
OSdigieverds-2105_pro_firmware3.1.0.71-11--

Explore more