Impact
The vulnerability identified in Ziroom ZHOME A0101 1.0.1.0 allows an attacker to execute arbitrary shell commands on the device. By supplying a crafted value to the ip argument in the /api/ZRQos/set_online_client endpoint, the application fails to properly sanitize user input, resulting in command injection. This flaw combines aspects of input validation weaknesses (CWE-74) and process control issues (CWE-77).
Affected Systems
Affected systems are the Ziroom ZHOME A0101 smart home device running firmware version 1.0.1.0. The vulnerability resides in the /api/ZRQos/set_online_client component of the device's API. No other versions or products are currently listed in the CVE data.
Risk and Exploitability
The CVSS score of 9.4 marks this as a critical severity, and the EPSS score is not available, but the lack of listing in the CISA KEV catalog does not diminish its potential impact. The exploit is disclosed publicly and can be triggered remotely over the network. Attackers with network access to the device could remotely inject and execute arbitrary commands, leading to full compromise of the device and potential lateral movement in the local network. Since no official patch was provided by the vendor, mitigation should focus on disabling the vulnerable endpoint, applying network restrictions, and monitoring for suspicious activity.
OpenCVE Enrichment