Description

An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input. The API is not enabled by default, and a valid API token is required to perform the attack.

INFO

Published Date :

2025-11-17T16:37:40.377Z

Last Modified :

2025-11-17T16:46:47.902Z

Source :

Digi
AFFECTED PRODUCTS

The following products are affected by CVE-2025-13319 vulnerability.

Vendors Products
Nettec
  • Digi On-prem Manager
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-13319.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact