Ziroom ZHOME A0101 firmware 1.0.1.0 has a command injection flaw in its network ping endpoint. An attacker can exploit it over the network, but only with high privileges on the device. A public exploit has already been released.
What Is It
CVE-2026-102794 is a command injection flaw in Ziroom ZHOME A0101 version 1.0.1.0. It is in the handling of the /api/ZRnetwork/ping file. An attacker can change the url argument to inject commands. VulDB is the CNA. It classifies the flaw as CWE-74 (Injection) and CWE-77 (Command Injection).
NVD has published the record. Its status is currently "Received," which means NVD has not yet analysed it.
Why It Matters
The CNA gives it a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The attack works over the network, has low complexity and needs no user interaction. Because the scope is changed, the impact can reach beyond the vulnerable component, with high impact on confidentiality, integrity and availability. The CVSS 4.0 score is 8.5 (HIGH), and the CVSS 2.0 score is 8.3 (HIGH).
The main limit is that the attacker needs high privileges (PR:H). Even so, the risk goes up for two reasons:
- A public exploit exists. According to the description, the exploit "has been disclosed to the public and may be used." The CVSS 4.0 data rates exploit maturity as Proof-of-Concept.
- The vendor has not responded. The vendor was contacted early about the disclosure and did not reply.
KEV status: No CISA KEV entry was supplied for this CVE. CISA has not confirmed active exploitation.
What's Vulnerable
- Vendor: Ziroom
- Product: ZHOME A0101
- Affected version: 1.0.1.0
- CPE:
cpe:2.3:a:ziroom:zhome_a0101:*:*:*:*:*:*:*:* - Affected component:
/api/ZRnetwork/ping, via theurlparameter
The source data does not list any other affected versions.
Patch Status
The source material does not mention a vendor patch or advisory. The vendor did not respond to the disclosure, so assume no fix is available for now. There is no CISA KEV entry, so no federal required action or remediation deadline applies.
Anyone running ZHOME A0101 1.0.1.0 should watch the VulDB and researcher references below for updates. Because the attack needs high privileges, it is worth reviewing who has privileged access to affected devices until a fix ships.