Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Digiever DS-2105 Pro Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Digiever DS-2105 Pro devices running version 3.1.0.71-11. This vulnerability allows authenticated users to inject commands through the 'time_tzsetup.cgi' CGI script. The issue arises because the device's management interface can be exposed to the Internet, potentially allowing unauthorized access.

Impact

Exploitation of this vulnerability allows for post-authentication remote code execution on the affected device.

Reproduction

To reproduce this vulnerability, an authenticated user must send a crafted request to the '/cgi-bin/cgi_main.cgi' endpoint, specifying 'cgiName=time_tzsetup.cgi' and injecting commands into the 'ntp' parameter. The injection can be verified by observing the execution of the injected commands on the device.

Remediation

Change the device's default username and password and avoid exposing the device to the Internet. If the device must be accessible online, use a firewall or gateway to proxy the management interface.

Added: Jun 9, 2025, 7:46 PM
Updated: Dec 22, 2025, 6:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.9
remediation
0.0
relevance
0.0
threat
9.9
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.