CVE-2025-15114
Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.56%
- CWE
- CWE-403
- Published
- 2025-12-30
- Last modified
- 2026-03-16
Affected products
- Ksenia Security S.p.A. lares
- Ksenia Security S.p.A. lares
Weakness type
Related vulnerabilities
- CVE-2026-33263 — When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with...
- CVE-2026-16526 — Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
- CVE-2026-40042 — Pachno 1.0.6 Wiki TextParser XML External Entity Injection
- CVE-2024-58280 — CMSimple 5.15 Remote Command Execution via Extensions Configuration
- CVE-2024-21626 — runc container breakout through process.cwd trickery and leaked fds