CVE-2026-101260 is a command injection flaw in firmware version 1.0.1.0 of the Ziroom ZHOME A0101. It can be exploited remotely through the /api/ZRnetwork/firstLogin endpoint, and a public exploit is available.
What Is It
The flaw is in the file /api/ZRnetwork/firstLogin on the Ziroom ZHOME A0101. The advisory does not say which function inside that file is affected. An attacker who manipulates the firstLogin argument can inject commands, and the attack works remotely. The CNA, VulDB, classifies the weakness as CWE-74 (Injection) and CWE-77 (Command Injection).
The flaw was published to NVD on 2026-09-28. Its status there is currently "Received," so NVD has not analyzed it yet.
Why It Matters
VulDB rates the flaw 9.1 (CRITICAL) under CVSS 3.1, with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H:
- Attack vector: network
- Attack complexity: low
- Privileges required: high
- User interaction: none
- Scope: changed
- Impact: high to confidentiality, integrity and availability
The CVSS 4.0 score is 8.5 (HIGH), and it records exploit maturity as Proof-of-Concept. According to the advisory, "the exploit is now public and may be used."
The high-privilege requirement narrows who can exploit this directly. Even so, a successful attack has a changed scope and high impact across the board, which means it could affect resources beyond the vulnerable component.
At the time of writing, CVE-2026-101260 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. This means CISA has not confirmed active exploitation in the wild.
What's Vulnerable
| Vendor | Product | Affected Version |
|---|---|---|
| Ziroom | ZHOME A0101 | 1.0.1.0 |
The CNA-supplied CPE is cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*. The record lists only version 1.0.1.0 as affected. Other versions are not listed as affected or as unaffected.
Patch Status
No patch or fixed version is listed in the source material. The advisory says Ziroom was contacted early about this disclosure but did not respond in any way. Because the CVE is not in the CISA KEV catalog at the time of writing, no federal required action or due date applies.
Owners of the ZHOME A0101 on version 1.0.1.0 should treat it as unpatched. They should also check whether the /api/ZRnetwork/firstLogin endpoint can be reached from networks they don't trust.