SQL Injection Vulnerability in Digi On-Prem Manager API
CVE-2025-13319
8.8HIGH
What is CVE-2025-13319?
An injection vulnerability allows attackers with valid API tokens to compromise the API feature in Digi On-Prem Manager. This flaw permits SQL code to be injected through specially crafted inputs. Although the API is not enabled by default, the presence of a valid token could lead to unauthorized access and data manipulation. Organizations using this product should implement stringent access controls and monitor API usage to mitigate potential threats.
Affected Version(s)
Digi On-Prem Manager Linux 24.12.5 < 25.08.5
