EXPOSURES › CVE-2023-52163
CVE-2023-52163
HIGH ⌖ ON CISA KEV · EXPLOITEDDigiever DS-2105 Pro exposed to command injection due to missing authorization, actively exploited in the wild
Digiever DS-2105 Pro, a network-attached storage (NAS) device, suffered a critical vulnerability that allowed attackers to execute arbitrary commands remotely via an unprotected administrative interface. This vulnerability has been actively exploited in the wild, posing a significant security risk to organizations using the device.
Shame score — Critical remote code execution vulnerability actively exploited in the wild
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.