cbcvebase.

Ziroom Zhome A0101 vulnerabilities

11 known vulnerabilities affecting ziroom/zhome_a0101.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-102792P2CRITICALCVSS 9.1v1.0.1.02026-09-29
CVE-2026-102792 [CRITICAL] CWE-74 CVE-2026-102792: A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this dis
nvd
CVE-2026-101187P2CRITICALCVSS 9.1v1.0.1.02026-09-28
CVE-2026-101187 [CRITICAL] CWE-74 CVE-2026-101187: A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the functio A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has b
nvd
CVE-2026-101262P2CRITICALCVSS 9.1v1.0.1.02026-09-28
CVE-2026-101262 [CRITICAL] CWE-74 CVE-2026-101262: A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown cod A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early
nvd
CVE-2026-102793P2CRITICALCVSS 9.1v1.0.1.02026-09-30
CVE-2026-102793 [CRITICAL] CWE-74 CVE-2026-102793: A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_tim A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted
nvd
CVE-2026-102794P2CRITICALCVSS 9.1v1.0.1.02026-09-30
CVE-2026-102794 [CRITICAL] CWE-74 CVE-2026-102794: A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown proces A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about
nvd
CVE-2026-101263P2CRITICALCVSS 9.1v1.0.1.02026-09-29
CVE-2026-101263 [CRITICAL] CWE-74 CVE-2026-101263: A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this
nvd
CVE-2026-101264P2CRITICALCVSS 9.1v1.0.1.02026-09-29
CVE-2026-101264 [CRITICAL] CWE-74 CVE-2026-101264: A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disc
nvd
CVE-2026-101260P2CRITICALCVSS 9.1v1.0.1.02026-09-28
CVE-2026-101260 [CRITICAL] CWE-74 CVE-2026-101260: A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown f A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was cont
nvd
CVE-2026-101261P2CRITICALCVSS 9.1v1.0.1.02026-09-28
CVE-2026-101261 [CRITICAL] CWE-74 CVE-2026-101261: A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/Z A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosur
nvd
CVE-2026-1802P2HIGHCVSS 7.3v1.0.1.02026-02-03
CVE-2026-1802 [HIGH] CWE-74 CVE-2026-1802: A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function m A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType results in command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was
nvd
CVE-2026-1803P3HIGHCVSS 8.1v1.0.1.02026-02-03
CVE-2026-1803 [HIGH] CWE-1392 CVE-2026-1803: A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made availab
nvd
Ziroom Zhome A0101 vulnerabilities | cvebase