Description
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability identified in Ziroom ZHOME A0101 1.0.1.0 allows an attacker to execute arbitrary shell commands on the device. By supplying a crafted value to the ip argument in the /api/ZRQos/set_online_client endpoint, the application fails to properly sanitize user input, resulting in command injection. This flaw combines aspects of input validation weaknesses (CWE-74) and process control issues (CWE-77).

Affected Systems

Affected systems are the Ziroom ZHOME A0101 smart home device running firmware version 1.0.1.0. The vulnerability resides in the /api/ZRQos/set_online_client component of the device's API. No other versions or products are currently listed in the CVE data.

Risk and Exploitability

The CVSS score of 9.4 marks this as a critical severity, and the EPSS score is not available, but the lack of listing in the CISA KEV catalog does not diminish its potential impact. The exploit is disclosed publicly and can be triggered remotely over the network. Attackers with network access to the device could remotely inject and execute arbitrary commands, leading to full compromise of the device and potential lateral movement in the local network. Since no official patch was provided by the vendor, mitigation should focus on disabling the vulnerable endpoint, applying network restrictions, and monitoring for suspicious activity.

Generated by OpenCVE AI on September 29, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ziroom firmware update that patches the /api/ZRQos/set_online_client command injection flaw (if available).
  • If no patch is available, restrict or block external access to the /api/ZRQos/set_online_client interface via firewall or device configuration.
  • Monitor device logs and network traffic for signs of command injection attempts and alert administrators.

Generated by OpenCVE AI on September 29, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Ziroom ZHOME A0101 set_online_client command injection
First Time appeared Ziroom
Ziroom zhome A0101
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*
Vendors & Products Ziroom
Ziroom zhome A0101
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Ziroom Zhome A0101
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T22:45:12.877Z

Reserved: 2026-09-28T11:31:22.045Z

Link: CVE-2026-101262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T23:17:01.187

Modified: 2026-09-28T23:17:01.187

Link: CVE-2026-101262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:45:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')