CVE & Vulnerabilities · October 2, 2026
A newly tracked vulnerability, CVE-2026-102793, hits the Ziroom ZHOME A0101 smart home hub running firmware 1.0.1.0, where the set_time_zone function behind its ZRFirmware API fails to sanitize the hostname or zone-name value it receives. That gap lets a remote attacker inject and execute arbitrary system commands without needing physical access to the device. A working exploit for the flaw is already public, and researchers say the vendor never responded after being notified ahead of disclosure.
// source: nvd.nist.gov ↗