Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.3之前版本存在授权问题漏洞,该漏洞源于授权问题(CWE-862),PERM_READ访问权限即可调用多个API端点,导致暴露AMI管理器密钥、出站拨号PIN、完整的Asterisk拨号计划环境、root SSH连接命令、备份工件路径、CDR历史记录、任意已保存的GraphQL查询执行以及包含密码、md5
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46512 | 9.9 CRITICAL | Frogman: Dialplan template parameters interpolated into extensions_custom.conf without esc |
| CVE-2026-46513 | 7.4 HIGH | Frogman: API tokens stored in plaintext |
| CVE-2026-46514 | 6.5 MEDIUM | Frogman: Plaintext passwords and secrets persisted to audit log |
No comments yet