Executive brief
AutohomeCorp frostmourne, a monitoring and alarm management platform, contains a security vulnerability in its Alarm Preview component. An attacker can exploit this flaw to perform unauthorized database queries, potentially leading to the exposure or modification of sensitive monitoring data. This could disrupt system alerting and compromise the integrity of operational logs.
Technical details
A SQL injection vulnerability exists in AutohomeCorp frostmourne version 1.0 within the 'httpTest' function of the '/api/monitor-api/alarm/previewData' endpoint. The flaw is located in the Alarm Preview component and stems from improper neutralization of special elements used in SQL commands (CWE-89). An attacker with low-level privileges can exploit this remotely over the network to execute arbitrary SQL queries. This can result in unauthorized data retrieval, modification, or deletion. A public proof-of-concept exploit has been released.
Affected products
- AutohomeCorp frostmourne 1.0
Timeline
- 2026-04-05: disclosed: Initial disclosure and publication of the CVE record.
- 2026-04-05: advisory: Advisory published by VulDB.