CVE-2026-101262 | Ziroom ZHOME A0101 1.0.1.0 set_online_client ip command injection
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0 and classified as very critical. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection.
This vulnerability is traded as CVE-2026-101262. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More