# CVE-2025-15113

## Summary

- **CVE ID:** CVE-2025-15113
- **Severity:** HIGH
- **CVSS Score:** 9.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-256
- **Published:** Dec 30, 2025
- **Last Modified:** Mar 16, 2026

## Description

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.

## Affected Products

- Ksenia Security S.p.A. — lares (1.6)
- Ksenia Security S.p.A. — lares (1.0.0.15)

## References

- [CNA](https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5930.php)
- [CNA](https://www.kseniasecurity.com/)
- [CNA](https://packetstorm.news/files/id/190178/)
- [CNA](https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-remote-code-execution-via-mpfs-upload)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._