Overview
A command injection vulnerability has been publicly disclosed in the Ziroom ZHOME A0101 smart home router/gateway, version 1.0.1.0. Tracked as CVE-2026-101187, the flaw resides in the pop_usb_device function of usr/lib/lua/luci/controller/api/zrUsb.lua, part of the device's USB Device Management API. By manipulating the path argument passed to this function, an attacker can inject and execute arbitrary operating system commands on the underlying device.
The vulnerability carries a CVSS score of 9.1 (Critical) and can be triggered remotely over the network. Unlike many router command-injection bugs that require no authentication at all, the associated CVSS vector indicates the attacker needs high-privilege access to the management API — meaning exploitation is most realistic when chained with credential compromise or another access-granting flaw. A working exploit has reportedly been made available publicly, and as of publication no vendor patch or advisory has been identified, raising the urgency for affected operators to apply compensating controls.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-101187 |
| Severity | Critical (CVSS 9.1) |
| Attack Vector | Network |
| Authentication | Required |
| Privileges Required | High |
| User Interaction | None |
| Impact | Arbitrary OS command execution on the device |
How It Works
zrUsb.lua is a LuCI (Lua Configuration Interface) controller module — the same web-management framework used by OpenWrt-derived router firmware — that exposes the device's USB Device Management API. The pop_usb_device function is responsible for handling requests to eject or "pop" an attached USB storage device, and it accepts a path argument identifying the target device node.
Based on the disclosed details, the path value is passed into a system-level command (consistent with the classic pattern of an unsanitized argument reaching os.execute, io.popen, or a shell-invoking system call in Lua-based router firmware) without adequate validation or escaping. An attacker who can reach this endpoint — with the required high-privilege session — can supply shell metacharacters in the path value to break out of the intended command and run arbitrary commands with whatever OS privileges the LuCI/uhttpd process holds. Because USB device paths are typically short strings under attacker influence during device enumeration workflows, this class of bug is a recurring pattern in embedded router firmware that shells out for hardware-management tasks instead of using safe, parameterized system calls.
Impact Assessment
Who Is At Risk
- Deployments of the Ziroom ZHOME A0101 running firmware 1.0.1.0 with the USB Device Management API reachable from an untrusted network or a compromised LAN segment
- Environments where administrative credentials for the device have been reused, defaulted, or otherwise weakened, since exploitation requires high-privilege access
- Ziroom-managed rental/smart-living properties and any other deployments relying on this gateway model for network and USB peripheral management
Potential Attack Chains
- Privilege Acquisition — An attacker obtains high-privilege access to the device's management API, whether through credential reuse, weak/default admin credentials, or by chaining one of the other command-injection flaws disclosed in the same firmware (several sibling CVEs affect authentication-adjacent endpoints in this release).
- Command Injection — The attacker sends a crafted request to the
pop_usb_deviceendpoint with shell metacharacters embedded in thepathargument. - Arbitrary Command Execution — The unsanitized value reaches a system-level call, executing attacker-controlled commands with the device's OS privileges.
- Post-Exploitation — The attacker uses the foothold to exfiltrate data from any attached USB storage, pivot to other devices on the LAN, or modify device configuration/firmware for persistence.
Mitigation
Immediate Actions
- Restrict access to the device's administrative/API interface to trusted management networks only; do not expose it to the internet
- Rotate and strengthen credentials used for administrative access, and eliminate any default or reused passwords
- Disable remote/USB management features on the device if they are not actively required
- Monitor vendor channels for a firmware update addressing CVE-2026-101187 — none has been confirmed as of this writing
Detection Opportunities
- Log and review requests to the
pop_usb_device/ USB Device Management API endpoint for shell metacharacters or unexpected path values - Watch for anomalous child processes spawned by the device's web-management (
uhttpd/LuCI) process - Monitor for unexpected USB mount/unmount activity or unfamiliar outbound connections originating from the device
Defence-in-Depth
- Segment IoT/router management interfaces onto a dedicated VLAN isolated from general user traffic
- Apply least-privilege principles to administrative accounts on embedded network devices
- Treat all LuCI-based/OpenWrt-derived consumer and smart-building gateways as high-value targets and include them in regular firmware and configuration audits
Background
Ziroom is a large Chinese long-term apartment rental and smart-living services operator, and ZHOME is its smart home gateway/router product line used to manage networking and connected devices across rental properties. CVE-2026-101187 is one of several command-injection vulnerabilities disclosed in the ZHOME A0101 firmware in the same batch, with related flaws reported in other API endpoints (including network setup, Wi-Fi provisioning, QoS client management, password/syslog configuration, and MAC address cloning). The recurrence of the same root cause — unsanitized arguments reaching shell-executing calls inside LuCI Lua controllers — across multiple endpoints suggests a systemic input-validation gap in this firmware's API layer rather than an isolated bug.
This pattern is common across consumer and SMB IoT/router firmware built on OpenWrt/LuCI foundations, where convenience functions that "shell out" to native Linux utilities for tasks like USB, network, or system configuration are a frequent source of command injection when developers assume inputs are trusted. Given the public availability of exploit details and the apparent lack of vendor response, defenders operating this device should prioritize network-level containment over waiting for a patch.