Description
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the /api/ZRnetwork/set_passwd endpoint of Ziroom ZHOME A0101 1.0.1.0. An attacker can manipulate the password1 parameter to inject arbitrary shell commands. This leads to execution of commands with the privileges of the device’s process, enabling full control over the device and potentially the local network it connects to.

Affected Systems

Ziroom ZHOME A0101 devices running firmware version 1.0.1.0 are impacted. The vendor identified the affected product as Ziroom:ZHOME A0101, and no other versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. Although an EPSS score or KEV listing is not available, the vulnerability is publicly disclosed and can be triggered remotely via a reachable API. Because the vendor has not released a patch, the likelihood of exploitation remains high for exposed devices.

Generated by OpenCVE AI on September 29, 2026 at 00:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied firmware update that addresses the command‑injection flaw.
  • If no patch is available, block the /api/ZRnetwork/set_passwd endpoint at the network perimeter.
  • Restrict access to the Ziroom device to trusted networks only, or isolate it using VLAN segmentation.
  • Actively monitor the device for abnormal shell activity and maintain log‑based alerting to detect potential exploitation attempts.

Generated by OpenCVE AI on September 29, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Ziroom ZHOME A0101 set_passwd command injection
First Time appeared Ziroom
Ziroom zhome A0101
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*
Vendors & Products Ziroom
Ziroom zhome A0101
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Ziroom Zhome A0101
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T23:15:14.158Z

Reserved: 2026-09-28T11:31:30.826Z

Link: CVE-2026-101264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:02.663

Modified: 2026-09-29T00:17:02.663

Link: CVE-2026-101264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T01:00:12Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')