Vulnerability Description
Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kseniasecurity | Lares Firmware | 1.6 |
| Kseniasecurity | Lares | 4.0 |
Related Weaknesses (CWE)
References
- https://packetstorm.news/files/id/190179/Third Party Advisory
- https://www.kseniasecurity.com/Product
- https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-url-rThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.phpThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.phpThird Party Advisory
FAQ
What is CVE-2025-15112?
CVE-2025-15112 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can ...
How severe is CVE-2025-15112?
CVE-2025-15112 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-15112?
Check the references section above for vendor advisories and patch information. Affected products include: Kseniasecurity Lares Firmware, Kseniasecurity Lares.