CRITICAL🇵🇱 Wersja polska

CVE-2025-15111

CVSS 9.3v4.0pub. 2025-12-30upd. 2026-03-11

Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

🤖 AI Analysis
How it works

The Ksenia Security Lares home automation system version 1.6 has built-in default login credentials for the administrator account, which are not changed during the configuration process. An attacker, remotely and without any authentication, can use these known credentials to log in to the administrative panel. No user interaction or special network conditions are required – access is possible directly through the network.

Impact

An attacker gains full administrative control over the home automation system, allowing them to read, modify, and disrupt the operation of managed devices and processes. The consequence may be compromise of confidentiality, integrity, and availability of the entire system.

Mitigation & patch

Default administrator credentials must be immediately changed to a strong, unique password. Patches available from the manufacturer should be applied in accordance with the provided references, and network access to the administrative panel should be restricted to trusted IP addresses only (e.g., through firewall or network segmentation).

Who is affected

Ksenia Security Lares (legacy model), firmware version 1.6

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Kseniasecurity Lares

    HW
    Kseniasecurity
    4.0
  • Kseniasecurity Lares Firmware

    OS
    Kseniasecurity
    1.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-15113CRITICAL9.3PL ✓same product

RCE w Ksenia Security Lares przez niezabezpieczony endpoint uploadu MPFS

CVE-2025-15114CRITICAL9.3PL ✓same product

Ksenia Security Lares – ujawnienie kodu PIN systemu alarmowego

CVE-2025-15112MEDIUM5.1same product

Ksenia Security lares (model legacy) w wersji 1.6 zawiera podatność otwartego redirectu w skrypcie 'cmdOk.xml'...