Unprotected Endpoint Vulnerability in Ksenia Security Lares 4.0 Home Automation
CVE-2025-15113
Key Information:
- Vendor
Ksenia Security S.p.a.
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2025-15113?
An unprotected endpoint vulnerability exists in the Ksenia Security Lares 4.0 Home Automation version 1.6. This flaw enables authenticated attackers to upload MPFS File System binary images, which can lead to the overwriting of flash program memory. By exploiting this weakness, attackers may execute arbitrary code on the home automation system's web server, potentially compromising the integrity and functionality of the system.
Affected Version(s)
Ksenia Security Lares 4.0 Home Automation 1.6
Ksenia Security Lares 4.0 Home Automation 1.0.0.15
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
