CVE-2025-15114

K

senia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*

History

20 Feb 2026, 17:25

Type Values Removed Values Added
CWE CWE-403

18 Feb 2026, 15:18

Type Values Removed Values Added
Summary (en) Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication. (en) Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

13 Jan 2026, 21:02

Type Values Removed Values Added
References () https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-pin-exposure-vulnerability - () https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-pin-exposure-vulnerability - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.php - Third Party Advisory
CPE cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
CWE CWE-668
First Time Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware

02 Jan 2026, 15:15

Type Values Removed Values Added
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5929.php -

30 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 23:15

Updated : 2026-02-20 17:25


NVD link : CVE-2025-15114

Mitre link : CVE-2025-15114

CVE.ORG link : CVE-2025-15114


JSON object : View

Products Affected
CWE
CWE-668

Exposure of Resource to Wrong Sphere