Remote Command Injection in Ziroom ZHOME A0101 USB API
An unauthenticated remote command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0 allows attackers to execute arbitrary commands via the USB Device Management API.
CVE search metadata
CVE search record: CVE-2026-101187. Severity: critical. CVSS: 9.1. KEV: no. Product: ZHOME A0101 (1.0.1.0). Brief: Remote Command Injection in Ziroom ZHOME A0101 USB API. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101187/
A critical command injection vulnerability, tracked as CVE-2026-101187, has been identified in the USB Device Management API of the Ziroom ZHOME A0101 device, version 1.0.1.0. The flaw resides within the pop_usb_device function in the Lua script located at /usr/lib/lua/luci/controller/api/zrUsb.lua. An attacker can exploit this by injecting malicious shell commands into the 'path' argument handled by this function. As the component handles USB device management, the lack of input sanitization allows for remote, unauthenticated code execution on the underlying operating system of the device. Publicly available exploit code exists, increasing the risk of exploitation. The vendor has not responded to vulnerability disclosure attempts, and no patch is currently available.
Attack Chain
- Attacker performs network reconnaissance to identify accessible Ziroom ZHOME A0101 devices.
- Attacker interacts with the web-based USB Device Management API.
- Attacker constructs a malicious HTTP request targeting the
pop_usb_deviceendpoint. - Attacker inserts shell metacharacters (e.g., ;, |, or backticks) into the 'path' parameter.
- The
zrUsb.luascript improperly passes the tainted parameter to the system shell. - The system executes the injected commands with the privileges of the web service.
- Attacker achieves remote code execution for system control or persistent access.
Impact
Successful exploitation allows for full remote compromise of the Ziroom ZHOME A0101 device. Potential consequences include unauthorized access to connected USB media, device misconfiguration, and potential pivot points into internal networks if the device is deployed within a protected environment. Given the public availability of exploit code and lack of vendor response, devices remain at high risk of exploitation by remote threat actors.
Recommendation
- Isolate the management interface of the ZHOME A0101 device from the internet immediately to prevent remote exploitation.
- Implement network-level access control lists (ACLs) to restrict access to the device management API to trusted, internal IP addresses only.
- Monitor web server logs for suspicious HTTP requests containing shell metacharacters (e.g., semicolon, pipe, ampersand) within parameters directed at the
/api/zrUsb.luaendpoint. - Ensure firmware updates are audited, though the vendor has not yet provided a resolution for this specific vulnerability.
Immediate actions
Isolate Ziroom ZHOME A0101 management interfaces from the public internet.
Threat Hunt
Search web logs for requests to /api/zrUsb.lua containing shell metacharacters.
Data: Web server access logs
Mitigations
Implement network segmentation/ACLs to restrict access.
CVE-2026-101187