CVE-2026-102793: Ziroom ZHOME A0101 set_time_zone command injection
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function settimezone of the file /api/ZRFirmware/settimezone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely over the network. The provided severity vector indicates that high privileges are required, while no user interaction is required.
Which input is vulnerable?
The command injection is associated with manipulation of the hostname/zonename argument handled by the set_time_zone function at /api/ZRFirmware/set_time_zone.
Is exploit code available?
Yes. The available data states that an exploit has been published and may be used.
Is there a vendor response or fix available?
No vendor response or fix is identified in the provided data. The vendor was contacted early about the disclosure but did not respond.