A remotely exploitable command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 has a public exploit, a CVSS 3.1 score of 9.1 (Critical), and no response from the vendor.
What Is It
CVE-2026-102792 is a command injection vulnerability in the set_syslog function of the /api/ZRnetwork/set_syslog endpoint on the Ziroom ZHOME A0101. According to the NVD description, an attacker can inject commands by manipulating the conloglevel or log_size argument. The CNA (VulDB) maps the weakness to CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-77 (Command Injection).
NVD published the record on 2026-09-29. Its status is currently "Received."
Why It Matters
- Remote attack vector: The attack can be carried out over the network with low attack complexity and no user interaction.
- Public exploit: The NVD description says "the exploit is now public and may be used." The CVSS 4.0 vector marks exploit maturity as Proof-of-Concept (
E:P). - High impact: Confidentiality, integrity and availability impacts are all rated High. The CVSS 3.1 scope is Changed, meaning a successful attack can affect components beyond the vulnerable one.
- Precondition: High privileges are required (
PR:Hin CVSS 3.1 and 4.0;Au:Min CVSS 2.0). This limits exposure to attackers who already have privileged access to the API.
Scores from the CNA:
- CVSS 3.1: 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- CVSS 4.0: 8.5 High
- CVSS 2.0: 8.3 High
KEV status: The supplied CISA KEV data has no entry for this CVE. KEV does not currently confirm active exploitation in the wild.
What's Vulnerable
- Vendor: Ziroom
- Product: ZHOME A0101
- Affected version: 1.0.1.0
- CPE:
cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:* - Affected component:
/api/ZRnetwork/set_syslog(set_syslogfunction), parametersconloglevel/log_size
Patch Status
The supplied references include no vendor patch, advisory or fixed version. The NVD description says the vendor "was contacted early about this disclosure but did not respond in any way." Because the CVE is not in KEV, no CISA-required action or remediation deadline applies. Owners of affected devices should watch the references below for updates.