CVE-2026-101187 is a remotely exploitable command injection flaw in the USB Device Management API of Ziroom ZHOME A0101 firmware 1.0.1.0. A public exploit exists, and the vendor has not responded to disclosure.
What Is It
The flaw is in the pop_usb_device function, found in usr/lib/lua/luci/controller/api/zrUsb.lua, which is part of the device's USB Device Management API. The function does not properly handle the path argument, so an attacker who manipulates it can inject commands. The weakness is classified as CWE-74 (Injection) and CWE-77 (Command Injection).
VulDB is the CNA and assigned these scores:
- CVSS 3.1: 9.1 (Critical),
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H - CVSS 4.0: 8.5 (High), with exploit maturity rated Proof-of-Concept
- CVSS 2.0: 8.3 (High)
Why It Matters
- Remote attack: The attack works over the network with low complexity and needs no user interaction.
- Public exploit: According to the CVE description, "the exploit has been made available to the public and could be used for attacks." A write-up on GitHub covers the
pop_usb_devicepath injection. - Rated impact: VulDB's CVSS 3.1 vector rates the impact on confidentiality, integrity and availability as High. The vector also marks the scope as changed, meaning the impact could reach beyond the vulnerable component. These are the CNA's severity ratings, not a confirmed result of exploitation on real devices.
- Limiting factor: The attacker needs high privileges (PR:H), which narrows who can realistically exploit it.
- Not in KEV: CISA's Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so active exploitation in the wild is not confirmed.
What's Vulnerable
| Field | Value |
|---|---|
| Vendor | Ziroom |
| Product | ZHOME A0101 |
| Affected version | 1.0.1.0 |
| Component | USB Device Management API |
| File | usr/lib/lua/luci/controller/api/zrUsb.lua |
| Function / argument | pop_usb_device / path |
| CPE | cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:* |
The NVD record was published on 2026-09-28 and still has the status "Received," meaning NVD has not yet analyzed it.
Patch Status
No patch or vendor advisory is listed. According to the CVE description, the vendor was contacted early about the disclosure but did not respond. Because the CVE is not in KEV, there is no CISA-mandated required action or due date. Owners of ZHOME A0101 devices running 1.0.1.0 should treat the USB Device Management API as exposed until the vendor issues a fix.