CVE-2025-15112

K

senia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*

History

20 Feb 2026, 17:25

Type Values Removed Values Added
CWE CWE-601

19 Feb 2026, 20:25

Type Values Removed Values Added
Summary (en) Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain. (en) Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.

16 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 5.4

07 Jan 2026, 22:00

Type Values Removed Values Added
First Time Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware
CPE cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
References () https://packetstorm.news/files/id/190179/ - () https://packetstorm.news/files/id/190179/ - Third Party Advisory
References () https://www.kseniasecurity.com/ - () https://www.kseniasecurity.com/ - Product
References () https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-url-redirection-vulnerability - () https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-url-redirection-vulnerability - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php - Third Party Advisory

02 Jan 2026, 15:15

Type Values Removed Values Added
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php -

30 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 23:15

Updated : 2026-02-20 17:25


NVD link : CVE-2025-15112

Mitre link : CVE-2025-15112

CVE.ORG link : CVE-2025-15112


JSON object : View

Products Affected
CWE

No CWE.