Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102793 2026-09-29

CVE-2026-102793: Command Injection in Ziroom ZHOME A0101 set_time_zone API

"A command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 can be triggered remotely and has a published exploit. According to the CNA, the vendor did not respond to the disclosure."

A command injection flaw in Ziroom ZHOME A0101 firmware 1.0.1.0 can be triggered remotely and has a published exploit. According to the CNA, the vendor did not respond to the disclosure.

What Is It

CVE-2026-102793 is a command injection vulnerability in the set_time_zone function of Ziroom ZHOME A0101 version 1.0.1.0. It sits in the /api/ZRFirmware/set_time_zone endpoint. An attacker can inject commands by manipulating the hostname/zonename argument. The weakness is classified as CWE-74 (Injection) and CWE-77 (Command Injection).

VulDB, the CNA, has published the record. NVD lists its status as "Received," which means NVD hasn't finished its own analysis yet.

Why It Matters

According to the CNA, the attack can be launched remotely and an exploit has been published. The CVSS v4.0 score reflects this with an exploit maturity of Proof of Concept.

Scoring from the CNA:

Exploitation requires high privileges (PR:H), which limits who can attack the device. However, the scope change and high impact scores for subsequent systems mean a successful attack could reach beyond the device itself.

KEV status: This CVE is not in the CISA Known Exploited Vulnerabilities catalog. The supplied data does not confirm active exploitation in the wild.

What's Vulnerable

Patch Status

The source data lists no patch or fixed version. According to the CNA, Ziroom was contacted early about the disclosure but did not respond. There is no KEV entry, so CISA has set no required action or due date.

Until the vendor provides a fix, organizations running ZHOME A0101 1.0.1.0 should:

Sources