CVE-2026-101262 is a command injection flaw in firmware version 1.0.1.0 of the Ziroom ZHOME A0101 that can be exploited remotely through the ip argument of /api/ZRQos/set_online_client; a public exploit exists and the vendor has not responded.
What Is It
CVE-2026-101262 affects code in the file /api/ZRQos/set_online_client on the Ziroom ZHOME A0101. According to the CVE record, attackers can manipulate the ip argument to cause command injection. The weaknesses listed are CWE-74 (Injection) and CWE-77 (Command Injection).
VulDB is the CNA. It published the record on 2026-09-28, and NVD currently lists the record's status as "Received."
Why It Matters
- Remote attack: The record says the attack can be started remotely. The CVSS vectors show network access and low attack complexity.
- Public exploit: The CVE record says the exploit "has been disclosed to the public and may be used." The CVSS 4.0 vector sets exploit maturity to Proof-of-Concept.
- High severity: VulDB scores the flaw at CVSS 3.1 9.1 (CRITICAL) with vector
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The scope is changed, and confidentiality, integrity and availability impacts are all high. The secondary scores are CVSS 4.0 8.5 (HIGH) and CVSS 2.0 8.3 (HIGH). - Precondition: The attacker needs high privileges (
PR:H), which limits exposure somewhat. Anyone who has that access, or has taken over an administrative account, could inject commands. - Exploitation status: None of the sources cited below report exploitation in the wild. Defenders should check CISA's Known Exploited Vulnerabilities catalog for any later listing.
What's Vulnerable
| Vendor | Product | Affected Version |
|---|---|---|
| Ziroom | ZHOME A0101 | 1.0.1.0 |
The CNA's affected-product data includes the CPE cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*. The supplied data names no other versions.
Patch Status
The source data mentions no patch, fixed version or vendor advisory. The CVE record says the vendor "was contacted early about this disclosure but did not respond in any way." The cited sources also do not mention any CISA required action or due date.
Owners of ZHOME A0101 devices running 1.0.1.0 should treat the device as unpatched. They should also watch the references below for any vendor response or updates to the record.