Description
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Injection
Action: Patch Now
AI Analysis

Impact

The vulnerability allows an attacker to inject and execute arbitrary system commands by manipulating the "mac" parameter of the /api/ZRQos/set_online_client endpoint. This leads to full code execution on the Ziroom ZHOME A0101 device, exposing confidentiality, integrity, and availability of the system. The CVSS score of 9.4 indicates that the flaw is considered critical.

Affected Systems

The issue affects Ziroom ZHOME A0101 devices running firmware version 1.0.1.0. No other versions are listed as affected.

Risk and Exploitability

The flaw can be triggered remotely over the device’s HTTP interface, making it reachable from outside the local network if exposed. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the overall risk is driven by the high CVSS score and the public availability of an exploitation script. Attackers can potentially gain full control of the device out of band by sending a crafted request to the vulnerable API endpoint.

Generated by OpenCVE AI on September 29, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version or apply the vendor patch that resolves the command injection issue.
  • Restrict or block access to the /api/ZRQos/set_online_client endpoint from untrusted networks by configuring network firewalls or the device’s access control settings.
  • Implement monitoring of command execution logs and network traffic from the device to detect anomalous activity that may indicate exploitation.

Generated by OpenCVE AI on September 29, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Ziroom ZHOME A0101 set_online_client command injection
First Time appeared Ziroom
Ziroom zhome A0101
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*
Vendors & Products Ziroom
Ziroom zhome A0101
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Ziroom Zhome A0101
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T23:00:14.363Z

Reserved: 2026-09-28T11:31:25.871Z

Link: CVE-2026-101263

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:01.540

Modified: 2026-09-29T00:17:01.540

Link: CVE-2026-101263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:45:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')