CVE-2025-13319 – Authenticated SQL injection in API – Digi On-Prem Manager
CVE ID : CVE-2025-13319
Published : Nov. 17, 2025, 4:37 p.m. | 27 minutes ago
Description : An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input.
The API is not enabled by default, and a valid API token is required to perform the attack.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…