CVE-2026-102794 Ziroom ZHOME A0101 命令注入漏洞
影响攻击者可远程执行任意系统命令,完全控制设备
Ziroom ZHOME A0101 1.0.1.0 版本的 /api/ZRnetwork/ping 接口存在命令注入漏洞。攻击者通过操纵 url 参数注入系统命令,可远程发起攻击。该漏洞 PoC 已公开,厂商未作任何回应。
影响范围
Ziroom ZHOME A0101 版本 1.0.1.0,其他版本是否受影响暂无公开信息。
漏洞详情
漏洞位于 /api/ZRnetwork/ping 接口,该接口在处理 url 参数时未对用户输入进行充分过滤,直接将参数拼接进系统命令执行。攻击者构造包含命令分隔符的 url 参数即可注入并执行任意系统命令。该接口可远程访问,无需认证即可利用。
利用条件与风险
利用前提为设备 /api/ZRnetwork/ping 接口可被远程访问,且 PoC 已公开,实战利用门槛低,风险极高。
修复建议
厂商未发布修复方案,建议限制该接口的远程访问、部署网络隔离或 WAF 过滤 url 参数中的命令注入特征;关注厂商后续公告。
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.