Arbitrary File Read Vulnerability in Digiever DS-2105 Pro Devices by Digiever
CVE-2023-52164

5.1MEDIUM

Key Information:

Vendor

Digiever

Vendor
CVE Published:
3 February 2025

What is CVE-2023-52164?

The Digiever DS-2105 Pro 3.1.0.71-11 devices are exposed to an arbitrary file read vulnerability via the access_device.cgi interface. This issue arises in devices that are no longer maintained by the vendor, which means they do not receive security updates or patches. As a result, users of these unsupported models are at risk of unauthorized access to potentially sensitive files, leading to data breaches or further exploitation by malicious actors.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.