critical · CVSS v3 9.1 · CVSS v4 9.4
CVE-2026-101261
Ziroom ZHOME A0101 firmware 1.0.1.0 contains a command injection vulnerability in the /api/ZRnetwork/firstSetup_wifi endpoint. Remote attack
Overview
Ziroom ZHOME A0101 firmware 1.0.1.0 contains a command injection vulnerability in the /api/ZRnetwork/firstSetup_wifi endpoint. Remote attackers can supply a crafted login_pwd parameter to execute arbitrary commands. This flaw could allow full compromise of the device.
Description
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Confidentiality: attackers can read or modify device configuration. Integrity: arbitrary commands can alter firmware or settings. Availability: device may become unresponsive. Defenders: network administrators and IoT security teams.
Remediation
Apply the vendor-supplied firmware update that fixes input validation in /api/ZRnetwork/firstSetup_wifi. If no update is available, block or rate-limit access to the endpoint from untrusted networks. Use network segmentation and firewall rules to restrict remote access to the device.
Risk context
Critical severity with CVSS 9.1 indicates high exploitation potential. No EPSS data available. Immediate attention recommended.
Affected products
- Ziroom ZHOME A0101
Scores
- Severity
- critical
- CVSS v2
- 8.3
- CVSS v3
- 9.1
- CVSS v4
- 9.4
- EPSS
- —