CVE-2026-1802

A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType results in command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto una falla de seguridad en Ziroom ZHOME A0101 1.0.1.0. Este problema afecta la función macAddrClone del archivo luci\controller\API\zrMacClone.lua. La manipulación del argumento macType resulta en inyección de comandos. El ataque puede ser lanzado de forma remota. El exploit ha sido publicado y puede ser utilizado para ataques. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

03 Feb 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 19:16

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1802

Mitre link : CVE-2026-1802

CVE.ORG link : CVE-2026-1802


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')