CVE & Vulnerabilities · October 1, 2026
A newly disclosed vulnerability, CVE-2026-101263, affects the Ziroom ZHOME A0101 smart home device running firmware 1.0.1.0. The flaw lies in the /api/ZRQos/set_online_client endpoint, where improper handling of the mac parameter lets a remote attacker inject and execute operating system commands. Exploit code is already public, and the vendor reportedly has not responded to the disclosure, leaving affected devices exposed.
// source: nvd.nist.gov ↗