{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-101260/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ziroom:zhome_a0101:1.0.1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-101187"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZHOME A0101 (1.0.1.0)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-101260","remote-code-execution","iot","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Ziroom"],"content_html":"\u003cp\u003eA critical command injection vulnerability, tracked as CVE-2026-101187, has been identified in the USB Device Management API of the Ziroom ZHOME A0101 device, version 1.0.1.0. The flaw resides within the \u003ccode\u003epop_usb_device\u003c/code\u003e function in the Lua script located at \u003ccode\u003e/usr/lib/lua/luci/controller/api/zrUsb.lua\u003c/code\u003e. An attacker can exploit this by injecting malicious shell commands into the 'path' argument handled by this function. As the component handles USB device management, the lack of input sanitization allows for remote, unauthenticated code execution on the underlying operating system of the device. Publicly available exploit code exists, increasing the risk of exploitation. The vendor has not responded to vulnerability disclosure attempts, and no patch is currently available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify accessible Ziroom ZHOME A0101 devices.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the web-based USB Device Management API.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious HTTP request targeting the \u003ccode\u003epop_usb_device\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inserts shell metacharacters (e.g., ;, |, or backticks) into the 'path' parameter.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ezrUsb.lua\u003c/code\u003e script improperly passes the tainted parameter to the system shell.\u003c/li\u003e\n\u003cli\u003eThe system executes the injected commands with the privileges of the web service.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution for system control or persistent access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote compromise of the Ziroom ZHOME A0101 device. Potential consequences include unauthorized access to connected USB media, device misconfiguration, and potential pivot points into internal networks if the device is deployed within a protected environment. Given the public availability of exploit code and lack of vendor response, devices remain at high risk of exploitation by remote threat actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIsolate the management interface of the ZHOME A0101 device from the internet immediately to prevent remote exploitation.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the device management API to trusted, internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious HTTP requests containing shell metacharacters (e.g., semicolon, pipe, ampersand) within parameters directed at the \u003ccode\u003e/api/zrUsb.lua\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eEnsure firmware updates are audited, though the vendor has not yet provided a resolution for this specific vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T00:23:39Z","date_published":"2026-09-28T22:22:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101187/","summary":"An unauthenticated remote command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0 allows attackers to execute arbitrary commands via the USB Device Management API.","title":"Remote Command Injection in Ziroom ZHOME A0101 USB API","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101187/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-101260","version":"https://jsonfeed.org/version/1.1"}