CVE-2026-101262 Ziroom ZHOME 命令注入漏洞
影响攻击者可远程执行任意命令,完全控制设备
Ziroom ZHOME A0101 1.0.1.0 的 /api/ZRQos/set_online_client 接口存在命令注入漏洞。攻击者通过操纵 ip 参数注入系统命令,可远程利用。该漏洞 PoC 已公开,厂商未作回应。
影响范围
Ziroom ZHOME A0101 版本 1.0.1.0 受影响,其他版本是否受影响暂无公开信息。
漏洞详情
漏洞类型为命令注入(Command Injection)。成因是 /api/ZRQos/set_online_client 接口未对 ip 参数做安全过滤,直接拼接进系统命令执行。攻击者可构造恶意 ip 值注入任意命令,且可远程发起。
利用条件与风险
利用无需认证或仅需低权限(具体前提暂无公开信息),PoC 已公开,实战风险高,可导致设备被完全控制。
修复建议
官方暂未发布修复方案,建议关注厂商公告;临时缓解可限制该接口的访问来源、对 ip 参数做严格校验或下线相关服务。
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.