VYPR

ZHOME A0101

by Ziroom

CVEs (6)

  • CVE-2026-101262CriSep 28, 2026
    risk 0.59cvss 9.1epss —

    A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-101261CriSep 28, 2026
    risk 0.59cvss 9.1epss —

    A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published…

  • CVE-2026-101260CriSep 28, 2026
    risk 0.59cvss 9.1epss —

    A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out…

  • CVE-2026-101187CriSep 28, 2026
    risk 0.59cvss 9.1epss —

    A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection.…

  • CVE-2026-1803HigFeb 3, 2026
    risk 0.53cvss 8.1epss 0.01

    A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high.…

  • CVE-2026-1802HigFeb 3, 2026
    risk 0.48cvss 7.3epss 0.04

    A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType results in command injection. The attack may be launched remotely. The exploit…