CVE detail
CVE-2025-13319 — CVE-2025-13319
Published 2025-11-17 · Modified 2026-06-17 · Source nvd
HIGH
severity
CVSS-derived band
0.0041
EPSS probability
exploitation probability, 30d
34.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input.
The API is not enabled by default, and a valid API token is required to perform the attack.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References