{"id":"CVE-2026-101262","published":"2026-09-28T23:17:01.187","lastModified":"2026-09-29T18:57:24.350","description":"A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-74","CWE-77"],"vendors":[],"products":[],"references":[{"url":"https://github.com/waltz-sketch/Ziroom/blob/main/set_online_client_ip_command_injection.md","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-101262","tags":[]},{"url":"https://vuldb.com/submit/914644","tags":[]},{"url":"https://vuldb.com/vuln/411030","tags":[]},{"url":"https://vuldb.com/vuln/411030/cti","tags":[]}],"exploitRefs":[{"url":"https://github.com/waltz-sketch/Ziroom/blob/main/set_online_client_ip_command_injection.md","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows command injection through the manipulation of the 'ip' argument, enabling remote attackers to execute arbitrary commands on the server.","exploitability":"Exploitation is relatively straightforward given the public disclosure of the exploit. Remote attackers can initiate the attack by manipulating the 'ip' argument.","blast_radius":"If exploited, this vulnerability could lead to complete control of the server, including data exfiltration, service disruption, and further lateral movement.","remediation":"Upgrade to Ziroom ZHOME A0101 1.0.1.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","command-injection","web","api"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:55:22.204Z"}}