Vulnerability Description
Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kseniasecurity | Lares Firmware | 1.6 |
| Kseniasecurity | Lares | 4.0 |
Related Weaknesses (CWE)
References
- https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-pin-eThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.phpThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.phpThird Party Advisory
FAQ
What is CVE-2025-15114?
CVE-2025-15114 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can ret...
How severe is CVE-2025-15114?
CVE-2025-15114 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-15114?
Check the references section above for vendor advisories and patch information. Affected products include: Kseniasecurity Lares Firmware, Kseniasecurity Lares.