Impact
The vulnerability allows an attacker to inject and execute arbitrary system commands by manipulating the "mac" parameter of the /api/ZRQos/set_online_client endpoint. This leads to full code execution on the Ziroom ZHOME A0101 device, exposing confidentiality, integrity, and availability of the system. The CVSS score of 9.4 indicates that the flaw is considered critical.
Affected Systems
The issue affects Ziroom ZHOME A0101 devices running firmware version 1.0.1.0. No other versions are listed as affected.
Risk and Exploitability
The flaw can be triggered remotely over the device’s HTTP interface, making it reachable from outside the local network if exposed. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the overall risk is driven by the high CVSS score and the public availability of an exploitation script. Attackers can potentially gain full control of the device out of band by sending a crafted request to the vulnerable API endpoint.
OpenCVE Enrichment