📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Higher Education CRITICAL 7h Global data_breach Government HIGH 8h Global supply_chain Software Development and Open Source Communities CRITICAL 8h Global malware Software Development CRITICAL 8h Global phishing Multiple Sectors HIGH 9h Global vulnerability Web Applications CRITICAL 9h Global apt Critical Infrastructure CRITICAL 9h Global ransomware Multiple sectors CRITICAL 10h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 10h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 11h Global vulnerability Higher Education CRITICAL 7h Global data_breach Government HIGH 8h Global supply_chain Software Development and Open Source Communities CRITICAL 8h Global malware Software Development CRITICAL 8h Global phishing Multiple Sectors HIGH 9h Global vulnerability Web Applications CRITICAL 9h Global apt Critical Infrastructure CRITICAL 9h Global ransomware Multiple sectors CRITICAL 10h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 10h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 11h Global vulnerability Higher Education CRITICAL 7h Global data_breach Government HIGH 8h Global supply_chain Software Development and Open Source Communities CRITICAL 8h Global malware Software Development CRITICAL 8h Global phishing Multiple Sectors HIGH 9h Global vulnerability Web Applications CRITICAL 9h Global apt Critical Infrastructure CRITICAL 9h Global ransomware Multiple sectors CRITICAL 10h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 10h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 11h
Vulnerabilities

CVE-2026-1802

High
A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType
CWE-74 — Weakness Type
Published: Feb 3, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.3
🔗 NVD Official
📄 Description (English)

A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType results in command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

🤖 AI Executive Summary

CVE-2026-1802 is a remote command injection vulnerability in Ziroom ZHOME A0101 smart home device firmware version 1.0.1.0, affecting the macAddrClone function. An attacker can manipulate the macType parameter to execute arbitrary commands remotely without authentication. With a CVSS score of 7.3 and public exploit availability, this poses significant risk to connected smart home deployments across Saudi Arabia.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 5, 2026 14:09
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi residential and commercial smart home deployments, particularly affecting: (1) Real estate and property management companies using Ziroom ZHOME systems for tenant management; (2) Telecommunications providers (STC, Mobily, Zain) offering smart home bundles; (3) Government smart city initiatives and housing projects; (4) Healthcare facilities using IoT-connected smart building systems. Compromised devices could enable lateral network movement into corporate networks, data exfiltration, and botnet recruitment for DDoS attacks targeting Saudi critical infrastructure.
🏢 Affected Saudi Sectors
Real Estate & Property Management Telecommunications (STC, Mobily, Zain) Government & Smart City Initiatives Healthcare Facilities Residential & Commercial Smart Home Hospitality & Hotels
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Ziroom ZHOME A0101 devices running firmware 1.0.1.0 in your network using network scanning tools (nmap, Shodan queries for 'Ziroom')
2. Isolate affected devices to a segregated VLAN with restricted outbound access
3. Disable remote management features and change default credentials immediately
4. Monitor for suspicious command execution patterns in device logs

PATCHING:
1. Contact Ziroom support for firmware updates beyond 1.0.1.0
2. If patch unavailable, implement network-level controls: block direct internet access to devices, require VPN for remote access
3. Deploy WAF rules to filter malicious macType parameter patterns (regex: [;|&`$(){}\[\]<>])

DETECTION:
1. Monitor HTTP POST requests to /luci/controller/api/zrMacClone with suspicious macType values
2. Alert on command injection payloads: semicolons, pipes, backticks, command substitution syntax
3. Log all API calls to zrMacClone endpoint and correlate with system command execution
4. Implement IDS signatures for CWE-74 command injection patterns

COMPENSATING CONTROLS:
1. Implement network segmentation isolating IoT devices from critical systems
2. Deploy API gateway with input validation and rate limiting
3. Enable detailed audit logging on all network-connected smart home devices
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Ziroom ZHOME A0101 التي تعمل بالإصدار 1.0.1.0 في شبكتك باستخدام أدوات المسح (nmap، استعلامات Shodan)
2. عزل الأجهزة المتأثرة في VLAN منفصل مع وصول خارجي مقيد
3. تعطيل ميزات الإدارة البعيدة وتغيير بيانات الاعتماد الافتراضية فوراً
4. مراقبة أنماط تنفيذ الأوامر المريبة في سجلات الجهاز

التصحيح:
1. الاتصال بدعم Ziroom للحصول على تحديثات البرامج الثابتة
2. إذا لم يكن التصحيح متاحاً، تطبيق عناصر التحكم على مستوى الشبكة: حظر الوصول المباشر للإنترنت، طلب VPN للوصول البعيد
3. نشر قواعد WAF لتصفية أنماط معاملات macType الضارة

الكشف:
1. مراقبة طلبات HTTP POST إلى /luci/controller/api/zrMacClone بقيم macType مريبة
2. التنبيه على حمولات حقن الأوامر
3. تسجيل جميع استدعاءات API إلى نقطة نهاية zrMacClone
4. تطبيق توقيعات IDS لأنماط حقن الأوامر

عناصر التحكم البديلة:
1. تطبيق تقسيم الشبكة لعزل أجهزة IoT عن الأنظمة الحرجة
2. نشر بوابة API مع التحقق من صحة المدخلات وتحديد معدل الطلبات
3. تفعيل تسجيل التدقيق التفصيلي على جميع أجهزة المنزل الذكي المتصلة بالشبكة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Network segmentation and access control for IoT devices ECC 2024 A.6.2.1 - Vulnerability management and patch deployment ECC 2024 A.8.2.3 - Monitoring and logging of API/application access ECC 2024 A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.RA-1 - Asset management and inventory of connected devices SAMA CSF PR.AC-1 - Access control and authentication mechanisms SAMA CSF PR.IP-1 - Security patch management processes SAMA CSF DE.CM-1 - Detection and monitoring of anomalous activities
🟡 ISO 27001:2022
ISO 27001:2022 A.5.1 - Policies for information security ISO 27001:2022 A.8.1 - Asset management and inventory ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development and change management
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches for all system components PCI DSS 11.2 - Vulnerability scanning and remediation
📊 CVSS Score
7.3
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity High
CVSS Score7.3
CWECWE-74
EPSS2.14%
Exploit No
Patch ✓ Yes
Published 2026-02-03
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-74
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.