PT-2026-30433 · Autohomecorp · Frostmourne

Xcxr

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5563

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AutohomeCorp frostmourne versions up to 1.0
Description A security flaw exists in AutohomeCorp frostmourne up to version 1.0. The httpTest function within the Alarm Preview component, accessible via the file /api/monitor-api/alarm/previewData, is susceptible to SQL injection. This attack can be initiated remotely. The exploit for this issue has been publicly released.
Recommendations Versions prior to 1.0 should be updated. As a temporary workaround, consider restricting access to the /api/monitor-api/alarm/previewData endpoint until a patch is available.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5563

Affected Products

Frostmourne