Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101264 2026-09-28

Command Injection in Ziroom ZHOME A0101 set_passwd Endpoint (CVE-2026-101264)

"A command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 can be triggered remotely. It has been publicly disclosed, and the vendor did not respond when contacted."

A command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 can be triggered remotely. It has been publicly disclosed, and the vendor did not respond when contacted.

What Is It

CVE-2026-101264 is a command injection vulnerability in the Ziroom ZHOME A0101, version 1.0.1.0. The flaw is in an unspecified function behind the /api/ZRnetwork/set_passwd endpoint. An attacker can inject commands by manipulating the password1 argument.

VulDB is the CVE Numbering Authority for this record. It classifies the weakness as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-77 (Command Injection). The NVD record is in "Received" status and has not yet been analyzed.

Why It Matters

What's Vulnerable

Vendor Product Affected Version
Ziroom ZHOME A0101 1.0.1.0

The vulnerable component is /api/ZRnetwork/set_passwd, specifically the password1 parameter. The cited sources list no other affected versions.

Patch Status

None of the cited sources reference a patch or vendor advisory. VulDB reports that the vendor was contacted early about the disclosure but did not respond. Owners of ZHOME A0101 1.0.1.0 devices should assume the device is unpatched. Until the vendor releases a fix, they should restrict who can reach its management API.

Sources