A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. (CVE-2026-102794)
A command injection vulnerability exists in Ziroom ZHOME A0101 version 1.0.1.0 in the processing of the /api/ZRnetwork/ping endpoint. This flaw allows remote attackers with high privileges to execute arbitrary commands by manipulating the 'url' argument. The vulnerability has a high severity with a CVSS score of 9.1. The vendor was notified but has not responded or issued a patch. Public exploit details are available, increasing the risk of exploitation.
AI Analysis
Technical Summary
CVE-2026-102794 describes a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The issue arises from improper handling of the 'url' parameter in the /api/ZRnetwork/ping endpoint, enabling remote command execution. The vulnerability requires high privileges and no user interaction. The vendor has not provided a fix or response. The CVSS v3.1 score is 9.1, indicating critical impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation can lead to complete system compromise including full control over the affected device, resulting in confidentiality, integrity, and availability loss. Because the vulnerability allows remote command injection, attackers can execute arbitrary commands remotely with high privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or issued a fix, users should consider mitigating exposure by restricting access to the vulnerable endpoint and monitoring for suspicious activity until an official patch is released.
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. (CVE-2026-102794)
Description
A command injection vulnerability exists in Ziroom ZHOME A0101 version 1.0.1.0 in the processing of the /api/ZRnetwork/ping endpoint. This flaw allows remote attackers with high privileges to execute arbitrary commands by manipulating the 'url' argument. The vulnerability has a high severity with a CVSS score of 9.1. The vendor was notified but has not responded or issued a patch. Public exploit details are available, increasing the risk of exploitation.
CVSS v3.1
Score 9.1critical
Affected software
pkg:github/waltz-sketch/ZiroomRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102794 describes a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The issue arises from improper handling of the 'url' parameter in the /api/ZRnetwork/ping endpoint, enabling remote command execution. The vulnerability requires high privileges and no user interaction. The vendor has not provided a fix or response. The CVSS v3.1 score is 9.1, indicating critical impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation can lead to complete system compromise including full control over the affected device, resulting in confidentiality, integrity, and availability loss. Because the vulnerability allows remote command injection, attackers can execute arbitrary commands remotely with high privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or issued a fix, users should consider mitigating exposure by restricting access to the vulnerable endpoint and monitoring for suspicious activity until an official patch is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qr4w-cmjh-rw2w
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102794"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc5d44680226ef6899ba61
Added to database: 09/30/2026, 00:52:20 UTC
Last enriched: 09/30/2026, 01:06:34 UTC
Last updated: 09/30/2026, 01:27:37 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.