CVE-2025-15111

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-30 23:15

Updated : 2026-01-16 19:16


NVD link : CVE-2025-15111

Mitre link : CVE-2025-15111

CVE.ORG link : CVE-2025-15111


JSON object : View

Products Affected

kseniasecurity

  • lares
  • lares_firmware
CWE
CWE-798

Use of Hard-coded Credentials