<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ziroom - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/ziroom/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 22:22:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/ziroom/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in Ziroom ZHOME A0101 USB API</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101187/</link><pubDate>Mon, 28 Sep 2026 22:22:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101187/</guid><description>An unauthenticated remote command injection vulnerability in Ziroom ZHOME A0101 version 1.0.1.0 allows attackers to execute arbitrary commands via the USB Device Management API.</description><content:encoded><![CDATA[<p>A critical command injection vulnerability, tracked as CVE-2026-101187, has been identified in the USB Device Management API of the Ziroom ZHOME A0101 device, version 1.0.1.0. The flaw resides within the <code>pop_usb_device</code> function in the Lua script located at <code>/usr/lib/lua/luci/controller/api/zrUsb.lua</code>. An attacker can exploit this by injecting malicious shell commands into the 'path' argument handled by this function. As the component handles USB device management, the lack of input sanitization allows for remote, unauthenticated code execution on the underlying operating system of the device. Publicly available exploit code exists, increasing the risk of exploitation. The vendor has not responded to vulnerability disclosure attempts, and no patch is currently available.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify accessible Ziroom ZHOME A0101 devices.</li>
<li>Attacker interacts with the web-based USB Device Management API.</li>
<li>Attacker constructs a malicious HTTP request targeting the <code>pop_usb_device</code> endpoint.</li>
<li>Attacker inserts shell metacharacters (e.g., ;, |, or backticks) into the 'path' parameter.</li>
<li>The <code>zrUsb.lua</code> script improperly passes the tainted parameter to the system shell.</li>
<li>The system executes the injected commands with the privileges of the web service.</li>
<li>Attacker achieves remote code execution for system control or persistent access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full remote compromise of the Ziroom ZHOME A0101 device. Potential consequences include unauthorized access to connected USB media, device misconfiguration, and potential pivot points into internal networks if the device is deployed within a protected environment. Given the public availability of exploit code and lack of vendor response, devices remain at high risk of exploitation by remote threat actors.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Isolate the management interface of the ZHOME A0101 device from the internet immediately to prevent remote exploitation.</li>
<li>Implement network-level access control lists (ACLs) to restrict access to the device management API to trusted, internal IP addresses only.</li>
<li>Monitor web server logs for suspicious HTTP requests containing shell metacharacters (e.g., semicolon, pipe, ampersand) within parameters directed at the <code>/api/zrUsb.lua</code> endpoint.</li>
<li>Ensure firmware updates are audited, though the vendor has not yet provided a resolution for this specific vulnerability.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>