CRITICAL🇵🇱 Wersja polska

CVE-2025-15113

CVSS 9.3v3.1pub. 2025-12-30upd. 2026-03-11

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.

🤖 AI Analysis
How it works

The system exposes an endpoint for uploading binary MPFS file system images, which is not properly protected despite requiring authentication. An attacker with access to an account (even with low privileges) can upload a crafted MPFS binary image through this endpoint. The uploaded file overwrites the device's flash memory, which can lead to arbitrary code execution (RCE) on the embedded web server of the home automation system. The vulnerability is also related to improper storage of authentication credentials (CWE-256, CWE-522).

Impact

An attacker can overwrite the device's flash memory and execute arbitrary code on the web server of the home automation system, which may result in complete takeover of the device and consequently the connected elements of the home installation.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. If no update is available, it is recommended to isolate the device from the public network, restrict access to the web interface only to trusted hosts, and monitor attempts at unauthorized file uploads.

Who is affected

Ksenia Security Lares Home Automation version 1.6 (legacy model) — Kseniasecurity Lares firmware software.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Kseniasecurity Lares

    HW
    Kseniasecurity
    4.0
  • Kseniasecurity Lares Firmware

    OS
    Kseniasecurity
    1.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-15111CRITICAL9.3PL ✓same product

Domyślne dane uwierzytelniające w Ksenia Security Lares – pełny dostęp administracyjny

CVE-2025-15114CRITICAL9.3PL ✓same product

Ksenia Security Lares – ujawnienie kodu PIN systemu alarmowego

CVE-2025-15112MEDIUM5.1same product

Ksenia Security lares (model legacy) w wersji 1.6 zawiera podatność otwartego redirectu w skrypcie 'cmdOk.xml'...