A critical command injection vulnerability in Ziroom ZHOME A0101 firmware 1.0.1.0 can be exploited remotely through the mac parameter of the /api/ZRQos/set_online_client endpoint. A public exploit is already available.
What Is It
CVE-2026-101263 is a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw is in how the device processes the file /api/ZRQos/set_online_client. When the mac argument is manipulated, attacker-supplied commands get injected. The weakness is classified as CWE-74 (Injection) and CWE-77 (Command Injection).
VulDB is the CVE Numbering Authority (CNA) for this entry.
Why It Matters
VulDB rates the flaw 9.1 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). The attack can be launched over the network with low complexity and needs no user interaction. The scope is marked as changed, and a successful attack has high impact on confidentiality, integrity and availability. The CVSS 4.0 score is 8.5 HIGH.
The main limiting factor is that the attack requires high privileges, so an attacker needs privileged access before exploiting it.
The exploit has been disclosed publicly, and the CVSS 4.0 vector sets exploit maturity to Proof-of-Concept. There is no CISA Known Exploited Vulnerabilities (KEV) entry for this CVE, so CISA has not confirmed active exploitation in the wild.
What's Vulnerable
- Vendor: Ziroom
- Product: ZHOME A0101
- Affected version: 1.0.1.0
- Vulnerable component:
/api/ZRQos/set_online_client(macargument)
The source data does not list any other affected versions.
Patch Status
The source data mentions no patch or fixed version. According to the disclosure, the vendor was contacted early but did not respond. There is no CISA KEV entry, so there is no KEV required action or due date.
Until the vendor responds, organizations running ZHOME A0101 1.0.1.0 should treat the device as unpatched. Restricting network access to its management API and to privileged accounts reduces exposure.