rootpwn

critical · CVSS v3 9.1 · CVSS v4 9.4

CVE-2026-101261

Ziroom ZHOME A0101 firmware 1.0.1.0 contains a command injection vulnerability in the /api/ZRnetwork/firstSetup_wifi endpoint. Remote attack

Overview

Ziroom ZHOME A0101 firmware 1.0.1.0 contains a command injection vulnerability in the /api/ZRnetwork/firstSetup_wifi endpoint. Remote attackers can supply a crafted login_pwd parameter to execute arbitrary commands. This flaw could allow full compromise of the device.

Description

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: attackers can read or modify device configuration. Integrity: arbitrary commands can alter firmware or settings. Availability: device may become unresponsive. Defenders: network administrators and IoT security teams.

Remediation

Apply the vendor-supplied firmware update that fixes input validation in /api/ZRnetwork/firstSetup_wifi. If no update is available, block or rate-limit access to the endpoint from untrusted networks. Use network segmentation and firewall rules to restrict remote access to the device.

Risk context

Critical severity with CVSS 9.1 indicates high exploitation potential. No EPSS data available. Immediate attention recommended.

Affected products

  • Ziroom ZHOME A0101

Scores

Severity
critical
CVSS v2
8.3
CVSS v3
9.1
CVSS v4
9.4
EPSS
—

command-injection iot remote-exploit critical Ziroom ZHOME network-setup

← All CVEs