Sceawere
Vulnerability Detail
CVE-2026-101264UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ziroom ZHOME Command Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 7h ago
- Vendor
- Ziroom
- Product
- ZHOME A0101
- Attack Type
- Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-29T00:17:02.663Z",
"pubdate": "2026-09-29T00:17:02.663Z",
"executiveSummary": "A critical command injection vulnerability has been identified in the Ziroom ZHOME A0101 version 1.0.1.0, specifically located within the /api/ZRnetwork/set_passwd API endpoint. This security flaw stems from the improper sanitization of the 'password1' argument, allowing an unauthenticated remote attacker to execute arbitrary system commands on the underlying host operating system.\nThe vulnerability poses a severe risk to the confidentiality, integrity, and availability of the affected device. Successful exploitation grants the attacker the ability to perform unauthorized administrative actions, manipulate system configurations, or deploy persistent malicious payloads. Given that the exploit vector is remotely accessible and has been publicly disclosed, the potential for opportunistic exploitation is high. The vendor has remained unresponsive to disclosure attempts, leaving the vulnerability unpatched and the deployed devices exposed to ongoing threats.\nOrganizations utilizing the Ziroom ZHOME A0101 are advised to restrict network access to the device and monitor for suspicious traffic targeting the /api/ZRnetwork/set_passwd endpoint.",
"technicalDetails": "The vulnerability resides in the backend processing logic of the Ziroom ZHOME A0101 1.0.1.0 firmware, specifically targeting the /api/ZRnetwork/set_passwd function. The root cause of this security defect is the failure to implement rigorous input validation or secure parameter handling when processing the 'password1' argument provided during a request to the aforementioned API path.\nIn a standard execution flow, the application likely passes the user-supplied input directly to a system shell or an insecure wrapper function that executes operating system commands without proper escaping or argument separation. An attacker can leverage this by injecting shell metacharacters—such as semicolons (;), pipes (|), or backticks (`)—followed by arbitrary malicious payloads into the 'password1' field. When the backend receives the crafted request, it inadvertently interprets these injected characters as part of the command sequence, thereby executing the attacker's instructions with the privilege level of the web server process.\nThe attack flow involves the following stages: First, the attacker identifies the target endpoint, /api/ZRnetwork/set_passwd, which is exposed over the network. Second, the attacker constructs an HTTP request containing the malicious payload within the 'password1' parameter. Because the system performs no validation, the injected payload is processed by the underlying system interpreter. Third, the command executes, enabling the attacker to perform tasks such as reverse shell establishment, exfiltration of configuration files, or the installation of backdoors. The network exposure of this device, combined with the lack of requisite authentication for this specific endpoint, significantly lowers the barrier for exploitation.\nBecause the payload is executed directly on the system, the impact is comprehensive. A remote attacker can gain full control over the device, bypass secondary security controls, or move laterally into a internal network segment where the ZHOME device is installed. Since the vendor has not provided a patch to address the underlying injection primitive, the device remains fundamentally insecure against remote command execution attempts that leverage this interface."
}