Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 30 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication. | |
| Title | Ksenia Security Lares 4.0 Home Automation 1.6 PIN Exposure Vulnerability | |
| Weaknesses | CWE-403 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-30T22:41:47.116Z
Reserved: 2025-12-27T01:46:45.375Z
Link: CVE-2025-15114
No data.
Status : Received
Published: 2025-12-30T23:15:50.070
Modified: 2025-12-30T23:15:50.070
Link: CVE-2025-15114
No data.
OpenCVE Enrichment
No data.
Weaknesses