CVE-2026-101264: Ziroom ZHOME A0101 set_passwd command injection
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/setpasswd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The CVSS vector indicates high privileges are required (PR:H). Exploitation is remote and does not require user interaction.
Is exploitation likely to be practical?
A public exploit disclosure exists, and the issue is rated critical with a 9.1 CVSS score. The available data indicates the exploit may be used.
What remediation information is available?
No patch, workaround, or vendor response is identified in the available data. The vendor was contacted before disclosure but did not respond.