Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #8
Critical command injection flaw found in Ziroom ZHOME smart home app
Original: CVE-2026-102794: Ziroom ZHOME A0101 v1.0.1.0 is affected by a CRITICAL command injection flaw (CVSS 9.1) in /api/ZRnetwo
A critical vulnerability, tracked as CVE-2026-102794, has been disclosed in Ziroom ZHOME A0101 version 1.0.1.0. The command injection flaw, rated 9.1 on the CVSS scale, sits in the /api/ZRnetwork/ping endpoint. No patch is available and a public exploit already exists, so users are being urged to restrict access to affected devices and monitor their usage while awaiting a fix from Ziroom.
Why now: A public exploit is circulating for an unpatched critical vulnerability, raising immediate security concerns for Ziroom smart home users.
ZiroomZHOME A0101CVE-2026-102794
Evidence
- CVE-2026-102794: Ziroom ZHOME A0101 v1.0.1.0 is affected by a CRITICAL command injection flaw (CVSS 9.1) in /api/ZRnetwork/ping. No patch, public exploit out. Restrict access & monitor usage. https:// radar.offseq.com/threat/a-vuln… · offseq@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/434834