Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101260 2026-09-28

Ziroom ZHOME A0101 Command Injection (CVE-2026-101260) Has a Public Exploit and No Vendor Response

"CVE-2026-101260 is a command injection flaw in firmware version 1.0.1.0 of the Ziroom ZHOME A0101. It can be exploited remotely through the `/api/ZRnetwork/firstLogin` endpoint, and a public exploit is available."

CVE-2026-101260 is a command injection flaw in firmware version 1.0.1.0 of the Ziroom ZHOME A0101. It can be exploited remotely through the /api/ZRnetwork/firstLogin endpoint, and a public exploit is available.

What Is It

The flaw is in the file /api/ZRnetwork/firstLogin on the Ziroom ZHOME A0101. The advisory does not say which function inside that file is affected. An attacker who manipulates the firstLogin argument can inject commands, and the attack works remotely. The CNA, VulDB, classifies the weakness as CWE-74 (Injection) and CWE-77 (Command Injection).

The flaw was published to NVD on 2026-09-28. Its status there is currently "Received," so NVD has not analyzed it yet.

Why It Matters

VulDB rates the flaw 9.1 (CRITICAL) under CVSS 3.1, with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H:

The CVSS 4.0 score is 8.5 (HIGH), and it records exploit maturity as Proof-of-Concept. According to the advisory, "the exploit is now public and may be used."

The high-privilege requirement narrows who can exploit this directly. Even so, a successful attack has a changed scope and high impact across the board, which means it could affect resources beyond the vulnerable component.

At the time of writing, CVE-2026-101260 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. This means CISA has not confirmed active exploitation in the wild.

What's Vulnerable

Vendor Product Affected Version
Ziroom ZHOME A0101 1.0.1.0

The CNA-supplied CPE is cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*. The record lists only version 1.0.1.0 as affected. Other versions are not listed as affected or as unaffected.

Patch Status

No patch or fixed version is listed in the source material. The advisory says Ziroom was contacted early about this disclosure but did not respond in any way. Because the CVE is not in the CISA KEV catalog at the time of writing, no federal required action or due date applies.

Owners of the ZHOME A0101 on version 1.0.1.0 should treat it as unpatched. They should also check whether the /api/ZRnetwork/firstLogin endpoint can be reached from networks they don't trust.

Sources