CVE-2026-101262

CRITICALCVSS 9.12% EPSS๐Ÿงจ Public exploit (GreyNoise)

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Published 2026-09-28 ยท last modified 2026-09-29

Full record at NVD โ†—

โ† Get alerted the moment a CVE hits your gear โ€” subscribe free

Ncerio by BeyondNets ยท data from NVD, CISA KEV, EPSS.