Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101187 2026-09-28

Ziroom ZHOME A0101 USB API Command Injection (CVE-2026-101187)

"CVE-2026-101187 is a remotely exploitable command injection flaw in the USB Device Management API of Ziroom ZHOME A0101 firmware 1.0.1.0. A public exploit exists, and the vendor has not responded to disclosure."

CVE-2026-101187 is a remotely exploitable command injection flaw in the USB Device Management API of Ziroom ZHOME A0101 firmware 1.0.1.0. A public exploit exists, and the vendor has not responded to disclosure.

What Is It

The flaw is in the pop_usb_device function, found in usr/lib/lua/luci/controller/api/zrUsb.lua, which is part of the device's USB Device Management API. The function does not properly handle the path argument, so an attacker who manipulates it can inject commands. The weakness is classified as CWE-74 (Injection) and CWE-77 (Command Injection).

VulDB is the CNA and assigned these scores:

Why It Matters

What's Vulnerable

Field Value
Vendor Ziroom
Product ZHOME A0101
Affected version 1.0.1.0
Component USB Device Management API
File usr/lib/lua/luci/controller/api/zrUsb.lua
Function / argument pop_usb_device / path
CPE cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:*

The NVD record was published on 2026-09-28 and still has the status "Received," meaning NVD has not yet analyzed it.

Patch Status

No patch or vendor advisory is listed. According to the CVE description, the vendor was contacted early about the disclosure but did not respond. Because the CVE is not in KEV, there is no CISA-mandated required action or due date. Owners of ZHOME A0101 devices running 1.0.1.0 should treat the USB Device Management API as exposed until the vendor issues a fix.

Sources