Ksenia Security Lares 4.0 Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 22 Jan 2026 00:30:00 +0900

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 22 Jan 2026 00:00:00 +0900

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Sat, 17 Jan 2026 04:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Jan 2026 07:15:00 +0900

Type Values Removed Values Added
First Time appeared Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware
Weaknesses CWE-522
CPEs cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
Vendors & Products Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware

Mon, 05 Jan 2026 19:45:00 +0900

Type Values Removed Values Added
First Time appeared Ksenia Security
Ksenia Security lares 4.0 Home Automation
Vendors & Products Ksenia Security
Ksenia Security lares 4.0 Home Automation

Sat, 03 Jan 2026 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 08:00:00 +0900

Type Values Removed Values Added
Description Ksenia Security Lares 4.0 Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.
Title Ksenia Security Lares 4.0 Home Automation 1.6 Remote Code Execution via MPFS Upload
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-21T14:38:48.930Z

Reserved: 2025-12-27T01:46:43.993Z

Link: CVE-2025-15113

cve-icon Vulnrichment

Updated: 2026-01-02T14:23:47.627Z

cve-icon NVD

Status : Modified

Published: 2025-12-30T23:15:49.913

Modified: 2026-01-21T15:16:05.937

Link: CVE-2025-15113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-05T19:19:43Z

Weaknesses