216.73.216.6

CVE-2025-13319

· Published 17/11/2025 17:15 · Modified 18/11/2025 14:06

Labels: CVE-2025-13319 2025-11-17CVE-2025-13319CWE-20e8a6bb0b-e373-42b1-a5de-93e314325576

Essential information

Published
17/11/2025 17:15
Modified
18/11/2025 14:06
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input. The API is not enabled by default, and a valid API token is required to perform the attack.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
e8a6bb0b-e373-42b1-a5de-93e314325576
NVD
View on NVD

References