Impact
Frogman, a headless PBX control platform, allowed any user with PERM_READ permissions to invoke privileged commands such as fm_list_managers and fm_get_mcp_config. These commands exposed Asterisk Manager Interface secrets, outbound dial PINs, full dialplan context, root SSH command aliases, backup artifact paths, call detail records, and the raw AMI endpoint. In addition, attackers could execute arbitrary GraphQL queries, granting them the ability to run any query supported by the backend. The result is a serious breach of confidentiality.
Affected Systems
The affected product is Frogman, developed by mwtcmi. Versions prior to 1.6.3 are vulnerable. No other vendors are listed.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at present, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers would need an account with PERM_READ rights; from there, they can call the exposed read‑tier endpoints to harvest credentials and execute arbitrary GraphQL queries. Because the vulnerability exists at the API layer, it can be leveraged remotely unless network or RBAC restrictions prevent access.
OpenCVE Enrichment