Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102792 2026-09-29

CVE-2026-102792: Command Injection in Ziroom ZHOME A0101 set_syslog API

"A remotely exploitable command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 has a public exploit, a CVSS 3.1 score of 9.1 (Critical), and no response from the vendor."

A remotely exploitable command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 has a public exploit, a CVSS 3.1 score of 9.1 (Critical), and no response from the vendor.

What Is It

CVE-2026-102792 is a command injection vulnerability in the set_syslog function of the /api/ZRnetwork/set_syslog endpoint on the Ziroom ZHOME A0101. According to the NVD description, an attacker can inject commands by manipulating the conloglevel or log_size argument. The CNA (VulDB) maps the weakness to CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-77 (Command Injection).

NVD published the record on 2026-09-29. Its status is currently "Received."

Why It Matters

Scores from the CNA: - CVSS 3.1: 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 8.5 High - CVSS 2.0: 8.3 High

KEV status: The supplied CISA KEV data has no entry for this CVE. KEV does not currently confirm active exploitation in the wild.

What's Vulnerable

Patch Status

The supplied references include no vendor patch, advisory or fixed version. The NVD description says the vendor "was contacted early about this disclosure but did not respond in any way." Because the CVE is not in KEV, no CISA-required action or remediation deadline applies. Owners of affected devices should watch the references below for updates.

Sources