CVE-2025-15114
Last modified
CVE-2025-15114 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kseniasecurity | Lares Firmware | 1.6 |
References
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.phpThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.phpThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-15114?
How severe is CVE-2025-15114?
How do I fix CVE-2025-15114?
Are you affected by CVE-2025-15114?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
