CVE-2025-13319: Authenticated SQL injection in API - Digi On-Prem Manager
An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input.
The API is not enabled by default, and a valid API token is required to perform the attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13319?
CVE-2025-13319 is considered a critical injection vulnerability, allowing SQL injection via the API with valid API tokens.
How do I fix CVE-2025-13319?
To fix CVE-2025-13319, ensure that API access is disabled if not in use and monitor for unauthorized API token usage.
Who is affected by CVE-2025-13319?
CVE-2025-13319 affects users of the Digi On-Prem Manager with enabled API access and valid API tokens.
What causes CVE-2025-13319?
CVE-2025-13319 is caused by improper input validation in the API feature of Digi On-Prem Manager.
Is CVE-2025-13319 exploitable?
Yes, CVE-2025-13319 is exploitable by attackers who possess valid API tokens and can inject malicious SQL commands.