Ksenia Security Lares 4.0 Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.
History

Tue, 30 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description Ksenia Security Lares 4.0 Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.
Title Ksenia Security Lares 4.0 Home Automation 1.6 Remote Code Execution via MPFS Upload
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-30T22:41:46.694Z

Reserved: 2025-12-27T01:46:43.993Z

Link: CVE-2025-15113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-30T23:15:49.913

Modified: 2025-12-30T23:15:49.913

Link: CVE-2025-15113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.