Ziroom ZHOME A0101 Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Ziroom ZHOME A0101 router, specifically in version 1.0.1.0. The issue arises in the 'macAddrClone' function within the 'luci/controller/api/zrMacClone.lua' file. The vulnerability allows remote attackers to execute arbitrary commands by manipulating the 'macType' parameter in an HTTP POST request. This exploitation requires user authentication.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send an authenticated HTTP POST request to '/cgi-bin/luci/;stok=<your_stok>/api/ZRMacClone/mac_addr_clone'. Include a 'macType' parameter with a crafted value that exploits the command injection flaw, such as a payload that, once URL-decoded, executes a command and redirects the output.

Added: Feb 3, 2026, 7:36 PM
Updated: Feb 3, 2026, 7:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.3
remediation
0.0
relevance
2.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.