---
cve: "CVE-2026-101261"
severity: "CRITICAL"
cvss: 9.4
epss: "2.4%"
vendor: "Ziroom"
kev: false
exploited: false
published: "2026-09-28 23:17:01"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-10T15:10:16+02:00"
---

# CVE-2026-101261

> 9.4 CRITICAL · 🧪 PoC

## Beschreibung

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulDB**
- State: PUBLISHED
- Stand: 2026-10-01 15:12:17
- CNA-CVSS: **9.4** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Schwachstellen-Klasse

- **CWE-74** — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
- **CWE-77** — Improper Neutralization of Special Elements used in a Command ('Command Injection')
  The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

## Angriffsmuster (CAPEC)

- [CAPEC-10 — Buffer Overflow via Environment Variables](https://capec.mitre.org/data/definitions/10.html) _(Severity: High)_
- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-14 — Client-side Injection-induced Buffer Overflow](https://capec.mitre.org/data/definitions/14.html) _(Severity: High)_
- [CAPEC-101 — Server Side Include (SSI) Injection](https://capec.mitre.org/data/definitions/101.html) _(Severity: High)_
- [CAPEC-105 — HTTP Request Splitting](https://capec.mitre.org/data/definitions/105.html) _(Severity: High)_
- [CAPEC-108 — Command Line Execution through SQL Injection](https://capec.mitre.org/data/definitions/108.html) _(Severity: Very High)_
- [CAPEC-120 — Double Encoding](https://capec.mitre.org/data/definitions/120.html) _(Severity: Medium)_
- [CAPEC-135 — Format String Injection](https://capec.mitre.org/data/definitions/135.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)

## Referenzen

- <https://vuldb.com/vuln/411029>
- <https://vuldb.com/vuln/411029/cti>
- <https://vuldb.com/cve/CVE-2026-101261>
- <https://vuldb.com/submit/914643>
- <https://github.com/waltz-sketch/Ziroom/blob/main/firstsetup_wifi_login_pwd_command_injection.md>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-101261/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
