A remotely reachable command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 has a public exploit, and the vendor has not responded to the disclosure.
What Is It
CVE-2026-101261 is a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw is in the /api/ZRnetwork/firstSetup_wifi endpoint. An attacker can manipulate the login_pwd argument to inject commands. The CNA (VulDB) classifies the weakness as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-77 (Command Injection).
The attack can be carried out remotely. VulDB published the record to NVD on 2026-09-28. Its NVD status is "Received," so NVD has not yet done its own analysis.
Why It Matters
- Severity: CVSS 3.1 base score is 9.1 (CRITICAL), vector
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The CVSS 4.0 score is 8.5 (HIGH). - Impact: Confidentiality, integrity and availability impacts are all rated High. The scope is Changed, which means a successful attack can reach components beyond the vulnerable one.
- Exploit availability: The exploit is public. CVSS 4.0 rates exploit maturity as Proof-of-Concept, and a public write-up is linked in the references.
- Limiting factor: The attacker needs high privileges (PR:H). Attack complexity is low and no user interaction is needed.
- KEV status: This CVE is not in the CISA Known Exploited Vulnerabilities catalog. The supplied data does not confirm active exploitation in the wild.
What's Vulnerable
| Vendor | Product | Affected Version |
|---|---|---|
| Ziroom | ZHOME A0101 | 1.0.1.0 |
- CPE:
cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:* - Vulnerable component:
/api/ZRnetwork/firstSetup_wifi(login_pwdparameter)
The supplied data does not list any other affected versions.
Patch Status
No patch or vendor advisory is available. According to the CVE description, the vendor was contacted early about the disclosure but did not respond. There is no CISA KEV entry, so no federal remediation deadline or required action applies.
Organizations running ZHOME A0101 1.0.1.0 should treat the device as unpatched. With a public exploit available, they should limit who can reach its management API until the vendor provides a fix.