By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
Computing

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

News Room
Last updated: 2025/12/25 at 3:46 AM
News Room Published 25 December 2025
Share
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
SHARE

Dec 25, 2025Ravie LakshmananVulnerability / Endpoint Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2023-52163 (CVSS score: 8.8), relates to a case of command injection that allows post-authentication remote code execution.

“Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi,” CISA said.

Cybersecurity

The addition of CVE-2023-52163 to the KEV catalog comes in the multiple reports from Akamai and Fortinet about the exploitation of the flaw by threat actors to deliver botnets like Mirai and ShadowV2.

According to TXOne Research security researcher Ta-Lun Yen, the vulnerability, alongside an arbitrary file read bug (CVE-2023-52164, CVSS score: 5.1), remains unpatched due to the device reaching end-of-life (EoL) status.

Successful exploitation requires an attacker to be logged into the device and perform a crafted request. In the absence of a patch, it’s advised that users avoid exposing the device to the internet and change the default username and password.

CISA is also recommending that Federal Civilian Executive Branch (FCEB) agencies apply the necessary mitigations or discontinue use of the product by January 12, 2025, to secure their network from active threats.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability
Next Article Your car might just be the best place to listen to music Your car might just be the best place to listen to music
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How to Drive Traffic and Sales from TikTok
How to Drive Traffic and Sales from TikTok
Computing
The Best Nintendo Switch 2 Games for 2026
The Best Nintendo Switch 2 Games for 2026
News
The TechBeat: Leader or No Leader, That is the Question (12/25/2025) | HackerNoon
The TechBeat: Leader or No Leader, That is the Question (12/25/2025) | HackerNoon
Computing
9 best headphones under 0: The best budget options we’ve tested
9 best headphones under $100: The best budget options we’ve tested
News

You Might also Like

How to Drive Traffic and Sales from TikTok
Computing

How to Drive Traffic and Sales from TikTok

12 Min Read
The TechBeat: Leader or No Leader, That is the Question (12/25/2025) | HackerNoon
Computing

The TechBeat: Leader or No Leader, That is the Question (12/25/2025) | HackerNoon

7 Min Read
Mobileye Eyeq6Lplus SoC Support Being Worked On For Mainline Linux Kernel
Computing

Mobileye Eyeq6Lplus SoC Support Being Worked On For Mainline Linux Kernel

1 Min Read
Meituan expands instant retail, scales back community group-buying in unprofitable areas · TechNode
Computing

Meituan expands instant retail, scales back community group-buying in unprofitable areas · TechNode

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?