Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware
Weaknesses CWE-668
CPEs cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
Vendors & Products Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware

Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Ksenia Security
Ksenia Security lares 4.0 Home Automation
Vendors & Products Ksenia Security
Ksenia Security lares 4.0 Home Automation

Fri, 02 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
Title Ksenia Security Lares 4.0 Home Automation 1.6 PIN Exposure Vulnerability
Weaknesses CWE-403
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-02T14:38:28.109Z

Reserved: 2025-12-27T01:46:45.375Z

Link: CVE-2025-15114

cve-icon Vulnrichment

Updated: 2026-01-02T14:23:32.859Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-30T23:15:50.070

Modified: 2026-01-13T21:02:34.353

Link: CVE-2025-15114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-05T10:19:23Z

Weaknesses