SQL Injection Vulnerability in Digi On-Prem Manager API
CVE-2025-13319

8.8HIGH

Key Information:

Vendor

Nettec As

Vendor
CVE Published:
17 November 2025

What is CVE-2025-13319?

An injection vulnerability allows attackers with valid API tokens to compromise the API feature in Digi On-Prem Manager. This flaw permits SQL code to be injected through specially crafted inputs. Although the API is not enabled by default, the presence of a valid token could lead to unauthorized access and data manipulation. Organizations using this product should implement stringent access controls and monitor API usage to mitigate potential threats.

Affected Version(s)

Digi On-Prem Manager Linux 24.12.5 < 25.08.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13319 : SQL Injection Vulnerability in Digi On-Prem Manager API