Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.
The Ksenia Security Lares home automation system version 1.6 has built-in default login credentials for the administrator account, which are not changed during the configuration process. An attacker, remotely and without any authentication, can use these known credentials to log in to the administrative panel. No user interaction or special network conditions are required – access is possible directly through the network.
An attacker gains full administrative control over the home automation system, allowing them to read, modify, and disrupt the operation of managed devices and processes. The consequence may be compromise of confidentiality, integrity, and availability of the entire system.
Default administrator credentials must be immediately changed to a strong, unique password. Patches available from the manufacturer should be applied in accordance with the provided references, and network access to the administrative panel should be restricted to trusted IP addresses only (e.g., through firewall or network segmentation).
Ksenia Security Lares (legacy model), firmware version 1.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XKseniasecurity Lares
HWKseniasecurity4.0Kseniasecurity Lares Firmware
OSKseniasecurity1.6
Related vulnerabilities
RCE w Ksenia Security Lares przez niezabezpieczony endpoint uploadu MPFS
Ksenia Security Lares – ujawnienie kodu PIN systemu alarmowego
Ksenia Security lares (model legacy) w wersji 1.6 zawiera podatność otwartego redirectu w skrypcie 'cmdOk.xml'...