CVE-2026-101263: Ziroom ZHOME A0101 set_online_client command injection
Published Sep 28, 2026
·Updated
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/setonlineclient. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
Ziroom ZHOME A0101=1.0.1.0
Event History
Sep 28, 2026
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Sep 29, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need existing access to exploit this issue?
Yes. The supplied CVSS vector indicates high privileges are required, although the attack can be launched remotely once that access is available.
2
Is exploit code or exploit information publicly available?
Yes. The vulnerability report states that the exploit has been made public and could be used.
3
Is a vendor fix or response available?
No vendor response or fix is described. The vendor was contacted early about the disclosure but did not respond.