Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101262 2026-09-28

Ziroom ZHOME A0101 Command Injection (CVE-2026-101262)

"CVE-2026-101262 is a command injection flaw in firmware version 1.0.1.0 of the Ziroom ZHOME A0101 that can be exploited remotely through the `ip` argument of `/api/ZRQos/set_online_client`; a public exploit exists and…"

CVE-2026-101262 is a command injection flaw in firmware version 1.0.1.0 of the Ziroom ZHOME A0101 that can be exploited remotely through the ip argument of /api/ZRQos/set_online_client; a public exploit exists and the vendor has not responded.

What Is It

CVE-2026-101262 affects code in the file /api/ZRQos/set_online_client on the Ziroom ZHOME A0101. According to the CVE record, attackers can manipulate the ip argument to cause command injection. The weaknesses listed are CWE-74 (Injection) and CWE-77 (Command Injection).

VulDB is the CNA. It published the record on 2026-09-28, and NVD currently lists the record's status as "Received."

Why It Matters

What's Vulnerable

Vendor Product Affected Version
Ziroom ZHOME A0101 1.0.1.0

The CNA's affected-product data includes the CPE cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*. The supplied data names no other versions.

Patch Status

The source data mentions no patch, fixed version or vendor advisory. The CVE record says the vendor "was contacted early about this disclosure but did not respond in any way." The cited sources also do not mention any CISA required action or due date.

Owners of ZHOME A0101 devices running 1.0.1.0 should treat the device as unpatched. They should also watch the references below for any vendor response or updates to the record.

Sources