Impact
The vulnerability resides in the /api/ZRnetwork/set_passwd endpoint of Ziroom ZHOME A0101 1.0.1.0. An attacker can manipulate the password1 parameter to inject arbitrary shell commands. This leads to execution of commands with the privileges of the device’s process, enabling full control over the device and potentially the local network it connects to.
Affected Systems
Ziroom ZHOME A0101 devices running firmware version 1.0.1.0 are impacted. The vendor identified the affected product as Ziroom:ZHOME A0101, and no other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. Although an EPSS score or KEV listing is not available, the vulnerability is publicly disclosed and can be triggered remotely via a reachable API. Because the vendor has not released a patch, the likelihood of exploitation remains high for exposed devices.
OpenCVE Enrichment