CVE-2026-102794: Ziroom ZHOME A0101 ping command injection
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which devices should be prioritized for investigation?
Ziroom ZHOME A0101 devices running version 1.0.1.0 should be prioritized. The affected processing is associated with the /api/ZRnetwork/ping endpoint.
What level of attacker access is indicated by the available severity data?
The CVSS vector indicates high privileges are required, while the attack can be launched remotely and does not require user interaction. The impact is rated critical, with high confidentiality, integrity, and availability impact.
Is exploitation likely to be practical?
A public exploit has been disclosed and may be used. The vendor was contacted but did not respond, according to the disclosure information.