天下漏洞,尽知其名
CRITICAL

CVE-2026-101260 Ziroom ZHOME A0101 命令注入漏洞

影响攻击者可远程执行任意命令,完全控制设备

AI 研判

Ziroom ZHOME A0101 1.0.1.0 的 /api/ZRnetwork/firstLogin 接口存在命令注入漏洞。攻击者通过操纵 firstLogin 参数即可注入并执行系统命令,且利用方式已公开。厂商被提前联系但未作任何回应。

影响范围

Ziroom ZHOME A0101

Ziroom ZHOME A0101 版本 1.0.1.0 受影响,其他版本是否受影响暂无公开信息。

漏洞详情

该漏洞属于命令注入(Command Injection)。/api/ZRnetwork/firstLogin 接口在处理 firstLogin 参数时未做充分过滤,将用户可控输入拼接进系统命令执行流程,导致攻击者可注入任意命令。攻击可远程发起,且公开的 PoC 已可被直接利用。

利用条件与风险

攻击者无需认证即可通过网络远程访问该接口并注入命令,利用门槛低、PoC 已公开,实战风险极高,可导致设备被完全接管。

修复建议

厂商未回应,暂无官方补丁信息。临时缓解措施包括:限制该接口的网络访问、在网关/WAF 层过滤 firstLogin 参数中的命令注入特征,或暂停使用受影响设备。

原始情报

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.