---
id: CVE-2026-101263
title: Ziroom ZHOME A0101 set_online_client command injection
summary: >-
  A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects
  some unknown processing of the file /api/ZRQos/set_online_client. The
  manipulation of the argument mac results in command injection. It is possible
  to launch the…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'
cvssSource: cna
cwe:
  - CWE-77
  - CWE-74
vendor: Ziroom
product: ZHOME A0101
affected:
  - zhome_a0101 1.0.1.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T23:00:14.363Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-101263'
references:
  - url: 'https://vuldb.com/vuln/411031'
    label: VDB-411031 | Ziroom ZHOME A0101 set_online_client command injection
  - url: 'https://vuldb.com/vuln/411031/cti'
    label: 'VDB-411031 | CTI Indicators (IOB, IOC, TTP, IOA)'
  - url: 'https://vuldb.com/cve/CVE-2026-101263'
    label: CVE-2026-101263 | CVE Analysis and Report
  - url: 'https://vuldb.com/submit/914645'
    label: >-
      Submit #914645 | Ziroom ZHOME-A0101 1.0.1.0, Build 202004151405 Command
      Injection
  - url: >-
      https://github.com/waltz-sketch/Ziroom/blob/main/set_online_client_mac_command_injection.md
tags:
  - cve.org
ingestedAt: '2026-09-28T23:23:00.572Z'
---

## Overview

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `zhome_a0101 1.0.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
