Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101261 2026-09-28

CVE-2026-101261: Command Injection in Ziroom ZHOME A0101 Wi-Fi Setup API

"A remotely reachable command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 has a public exploit, and the vendor has not responded to the disclosure."

A remotely reachable command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 has a public exploit, and the vendor has not responded to the disclosure.

What Is It

CVE-2026-101261 is a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw is in the /api/ZRnetwork/firstSetup_wifi endpoint. An attacker can manipulate the login_pwd argument to inject commands. The CNA (VulDB) classifies the weakness as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-77 (Command Injection).

The attack can be carried out remotely. VulDB published the record to NVD on 2026-09-28. Its NVD status is "Received," so NVD has not yet done its own analysis.

Why It Matters

What's Vulnerable

Vendor Product Affected Version
Ziroom ZHOME A0101 1.0.1.0

The supplied data does not list any other affected versions.

Patch Status

No patch or vendor advisory is available. According to the CVE description, the vendor was contacted early about the disclosure but did not respond. There is no CISA KEV entry, so no federal remediation deadline or required action applies.

Organizations running ZHOME A0101 1.0.1.0 should treat the device as unpatched. With a public exploit available, they should limit who can reach its management API until the vendor provides a fix.

Sources