Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.
The system exposes an endpoint for uploading binary MPFS file system images, which is not properly protected despite requiring authentication. An attacker with access to an account (even with low privileges) can upload a crafted MPFS binary image through this endpoint. The uploaded file overwrites the device's flash memory, which can lead to arbitrary code execution (RCE) on the embedded web server of the home automation system. The vulnerability is also related to improper storage of authentication credentials (CWE-256, CWE-522).
An attacker can overwrite the device's flash memory and execute arbitrary code on the web server of the home automation system, which may result in complete takeover of the device and consequently the connected elements of the home installation.
Patches available from the manufacturer should be applied according to references. If no update is available, it is recommended to isolate the device from the public network, restrict access to the web interface only to trusted hosts, and monitor attempts at unauthorized file uploads.
Ksenia Security Lares Home Automation version 1.6 (legacy model) — Kseniasecurity Lares firmware software.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HKseniasecurity Lares
HWKseniasecurity4.0Kseniasecurity Lares Firmware
OSKseniasecurity1.6
Related vulnerabilities
Domyślne dane uwierzytelniające w Ksenia Security Lares – pełny dostęp administracyjny
Ksenia Security Lares – ujawnienie kodu PIN systemu alarmowego
Ksenia Security lares (model legacy) w wersji 1.6 zawiera podatność otwartego redirectu w skrypcie 'cmdOk.xml'...