Sceawere
Vulnerability Detail
CVE-2026-101263UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ziroom ZHOME Command Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 7h ago
- Vendor
- Ziroom
- Product
- ZHOME A0101
- Attack Type
- Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-29T00:17:01.540Z",
"pubdate": "2026-09-29T00:17:01.540Z",
"executiveSummary": "A critical command injection vulnerability has been identified in the Ziroom ZHOME A0101 version 1.0.1.0, specifically within the /api/ZRQos/set_online_client endpoint.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary system commands with the privileges of the underlying web service process.\nThe flaw originates from improper input validation of the 'mac' parameter, which is directly concatenated into a system shell command without sanitization.\nThe risk is severe as it enables full compromise of the affected device, potentially leading to unauthorized data access, persistence, or participation in botnet activities.\nThe vulnerability is currently exploited in the wild, and given the vendor's lack of response to disclosure, users remain at high risk of compromise.\nSuccessful exploitation requires no prior authentication and can be performed over a network, making the device highly susceptible to automated or targeted remote attacks.",
"technicalDetails": "The vulnerability resides in the /api/ZRQos/set_online_client API endpoint of the Ziroom ZHOME A0101 (version 1.0.1.0) firmware.\nThe root cause of this vulnerability is an OS command injection flaw occurring during the processing of the 'mac' argument. Application logic fails to perform adequate input validation or filtering on this parameter before passing the provided string to a system-level function or shell execution environment.\nThe exploitation method involves crafting a malicious HTTP request directed at the specified API endpoint. By injecting shell metacharacters such as backticks (``), semicolons (;), pipes (|), or command chaining operators (&&, ||) into the 'mac' field, an attacker can escape the intended application context and execute arbitrary system commands.\nThe attack flow proceeds as follows: 1) The attacker constructs an HTTP POST or GET request targeted at /api/ZRQos/set_online_client. 2) The attacker embeds a command payload within the 'mac' parameter (e.g., mac=00:00:00:00:00:00;[COMMAND]). 3) The ZHOME web server receives the request and parses the 'mac' parameter. 4) The backend application logic passes the unvalidated user input directly to a system shell command execution function (such as system() or popen()). 5) The shell interprets the injected metacharacters and executes the attacker's payload as a sub-process of the web server.\nBecause the web server typically runs with elevated privileges, the payload executes with the same permissions, granting the attacker control over the operating system environment. This allows for arbitrary code execution, including the ability to download additional malware, modify configuration files, or exfiltrate sensitive data stored on the device.\nThe lack of authentication requirements for accessing the /api/ZRQos/set_online_client endpoint significantly lowers the barrier to entry, allowing any remote actor with network visibility to the device to achieve full system compromise without needing credentials.\nPost-exploitation impact includes persistent unauthorized access, lateral movement within the network, and the potential for a complete device takeover, turning the ZHOME unit into an uncontrolled node within the attacker's infrastructure."
}