A command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 can be triggered remotely. It has been publicly disclosed, and the vendor did not respond when contacted.
What Is It
CVE-2026-101264 is a command injection vulnerability in the Ziroom ZHOME A0101, version 1.0.1.0. The flaw is in an unspecified function behind the /api/ZRnetwork/set_passwd endpoint. An attacker can inject commands by manipulating the password1 argument.
VulDB is the CVE Numbering Authority for this record. It classifies the weakness as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-77 (Command Injection). The NVD record is in "Received" status and has not yet been analyzed.
Why It Matters
- Severity: The CVSS 3.1 base score is 9.1 (CRITICAL), with vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The CVSS 4.0 score is 8.5 (HIGH) and the CVSS 2.0 score is 8.3 (HIGH). - Remote attack: The attack works over the network with low complexity and needs no user interaction.
- Privileges required: An attacker needs high privileges. In practice that means authenticated access to the device API.
- Impact: Confidentiality, integrity and availability impacts are all rated high. The scope is "Changed," so a successful exploit can affect resources beyond the vulnerable component.
- Public exploit: The exploit has been publicly disclosed and may be used. CVSS 4.0 rates exploit maturity as Proof-of-Concept.
- Exploitation status: None of the sources cited below report active exploitation in the wild. Check the CISA Known Exploited Vulnerabilities catalog for current status.
What's Vulnerable
| Vendor | Product | Affected Version |
|---|---|---|
| Ziroom | ZHOME A0101 | 1.0.1.0 |
The vulnerable component is /api/ZRnetwork/set_passwd, specifically the password1 parameter. The cited sources list no other affected versions.
Patch Status
None of the cited sources reference a patch or vendor advisory. VulDB reports that the vendor was contacted early about the disclosure but did not respond. Owners of ZHOME A0101 1.0.1.0 devices should assume the device is unpatched. Until the vendor releases a fix, they should restrict who can reach its management API.