天下漏洞,尽知其名
CRITICAL

CVE-2026-101263 Ziroom ZHOME A0101 命令注入漏洞

影响攻击者可远程执行任意命令

AI 研判

Ziroom ZHOME A0101 1.0.1.0 的 /api/ZRQos/set_online_client 接口存在命令注入漏洞。攻击者通过操纵 mac 参数即可注入并执行系统命令,且该漏洞利用方式已公开。厂商在收到披露后未作任何回应。

影响范围

Ziroom ZHOME A0101

Ziroom ZHOME A0101 1.0.1.0 版本受影响,其他版本是否受影响暂无公开信息。

漏洞详情

该漏洞属于命令注入类型,成因是 /api/ZRQos/set_online_client 接口在处理 mac 参数时未做充分过滤,直接将用户输入拼接进系统命令执行。攻击者可构造恶意 mac 值注入任意命令,从而在设备上执行。该接口可远程访问,利用门槛较低。

利用条件与风险

攻击者需能访问该 HTTP 接口,无需认证即可远程利用;由于利用代码已公开,实战中被扫描和攻击的风险较高。

修复建议

厂商未回应,暂无官方修复方案;建议限制该接口的网络访问、对 mac 参数进行严格校验与过滤,或部署 WAF 拦截命令注入特征。

原始情报

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.