CVE-2025-15114

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-30 23:15

Updated : 2026-01-13 21:02


NVD link : CVE-2025-15114

Mitre link : CVE-2025-15114

CVE.ORG link : CVE-2025-15114


JSON object : View

Products Affected

kseniasecurity

  • lares
  • lares_firmware
CWE
CWE-403

Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')

CWE-668

Exposure of Resource to Wrong Sphere