Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101263 2026-09-28

Ziroom ZHOME A0101 Command Injection Flaw (CVE-2026-101263) Has a Public Exploit and No Vendor Response

"A critical command injection vulnerability in Ziroom ZHOME A0101 firmware 1.0.1.0 can be exploited remotely through the `mac` parameter of the `/api/ZRQos/set_online_client` endpoint. A public exploit is already…"

A critical command injection vulnerability in Ziroom ZHOME A0101 firmware 1.0.1.0 can be exploited remotely through the mac parameter of the /api/ZRQos/set_online_client endpoint. A public exploit is already available.

What Is It

CVE-2026-101263 is a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw is in how the device processes the file /api/ZRQos/set_online_client. When the mac argument is manipulated, attacker-supplied commands get injected. The weakness is classified as CWE-74 (Injection) and CWE-77 (Command Injection).

VulDB is the CVE Numbering Authority (CNA) for this entry.

Why It Matters

VulDB rates the flaw 9.1 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). The attack can be launched over the network with low complexity and needs no user interaction. The scope is marked as changed, and a successful attack has high impact on confidentiality, integrity and availability. The CVSS 4.0 score is 8.5 HIGH.

The main limiting factor is that the attack requires high privileges, so an attacker needs privileged access before exploiting it.

The exploit has been disclosed publicly, and the CVSS 4.0 vector sets exploit maturity to Proof-of-Concept. There is no CISA Known Exploited Vulnerabilities (KEV) entry for this CVE, so CISA has not confirmed active exploitation in the wild.

What's Vulnerable

The source data does not list any other affected versions.

Patch Status

The source data mentions no patch or fixed version. According to the disclosure, the vendor was contacted early but did not respond. There is no CISA KEV entry, so there is no KEV required action or due date.

Until the vendor responds, organizations running ZHOME A0101 1.0.1.0 should treat the device as unpatched. Restricting network access to its management API and to privileged accounts reduces exposure.

Sources