A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. (CVE-2026-102792)
CVE-2026-102792 is a critical command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw exists in the set_syslog function of the /api/ZRnetwork/set_syslog endpoint, where manipulation of the conloglevel or log_size arguments allows remote attackers to execute arbitrary commands. The vulnerability has a high CVSS 4.0 score of 9.4, indicating severe impact. Exploit code is publicly available, but no vendor response or patch has been provided.
AI Analysis
Technical Summary
CVE-2026-102792 describes a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw is located in the set_syslog function within the /api/ZRnetwork/set_syslog file, where manipulation of the conloglevel or log_size parameters can lead to command injection. This vulnerability can be exploited remotely without user interaction but requires high privileges. Public exploit code is available, and the vendor has not issued any response or patch.
Potential Impact
Successful exploitation allows remote attackers with high privileges to execute arbitrary commands on the affected system, potentially leading to full system compromise. The vulnerability impacts confidentiality, integrity, and availability, as indicated by the CVSS vector (C:H/I:H/A:H).
Mitigation Recommendations
Patch status is not yet confirmed — no vendor response or official fix has been provided. Users should monitor vendor advisories for updates. Until a patch is available, restrict access to the vulnerable API endpoint and limit privileges to trusted users only.
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. (CVE-2026-102792)
Description
CVE-2026-102792 is a critical command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw exists in the set_syslog function of the /api/ZRnetwork/set_syslog endpoint, where manipulation of the conloglevel or log_size arguments allows remote attackers to execute arbitrary commands. The vulnerability has a high CVSS 4.0 score of 9.4, indicating severe impact. Exploit code is publicly available, but no vendor response or patch has been provided.
CVSS v3.1
Score 9.1critical
Affected software
pkg:github/waltz-sketch/ZiroomRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102792 describes a command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0. The flaw is located in the set_syslog function within the /api/ZRnetwork/set_syslog file, where manipulation of the conloglevel or log_size parameters can lead to command injection. This vulnerability can be exploited remotely without user interaction but requires high privileges. Public exploit code is available, and the vendor has not issued any response or patch.
Potential Impact
Successful exploitation allows remote attackers with high privileges to execute arbitrary commands on the affected system, potentially leading to full system compromise. The vulnerability impacts confidentiality, integrity, and availability, as indicated by the CVSS vector (C:H/I:H/A:H).
Mitigation Recommendations
Patch status is not yet confirmed — no vendor response or official fix has been provided. Users should monitor vendor advisories for updates. Until a patch is available, restrict access to the vulnerable API endpoint and limit privileges to trusted users only.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m655-382j-6799
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102792"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc5d44680226ef6899ba67
Added to database: 09/30/2026, 00:52:20 UTC
Last enriched: 09/30/2026, 01:06:27 UTC
Last updated: 09/30/2026, 01:27:32 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.