CVE-2025-15111
7.5Ksenia Security · lares
Ksenia Security lares version 1.6 contains a default credentials vulnerability that allows unauthenticated attackers to gain administrative access and full control of the home automation system.
Executive summary
A critical default credentials vulnerability in Ksenia Security lares systems allows unauthenticated attackers to gain full administrative control, presenting a significant risk to home automation security.
Vulnerability
The device uses hard-coded default administrative credentials, which can be leveraged by any unauthenticated attacker to bypass authentication mechanisms and achieve full control over the system.
Business impact
The exploitation of this vulnerability results in a total loss of confidentiality, integrity, and availability for the affected home automation system. Given the CVSS score of 7.5, this high-severity flaw enables unauthorized actors to manipulate home security, surveillance, or environmental controls, posing severe privacy and safety risks to users.
Remediation
Immediate Action: Administrators must change the default administrative passwords immediately and ensure that the device is not exposed directly to the public internet.
Proactive Monitoring: Review device access logs for unauthorized login attempts or administrative configuration changes originating from unknown IP addresses.
Compensating Controls: If the device must remain network-accessible, place it behind a secure VPN or a restricted firewall policy that limits access to trusted internal IP ranges only.
Exploitation status
Public Exploit Available: No (The provided reference is a third-party security advisory and does not constitute a weaponized exploit or functional proof-of-concept code).
Analyst recommendation
The presence of hard-coded credentials in a system managing physical home security is a critical risk that requires immediate attention. Organizations and users should prioritize changing these default credentials to strong, unique passwords and restrict network exposure to prevent potential exploitation. Failure to address this vulnerability leaves the system open to full unauthorized takeover by external attackers.
More Ksenia Security CVEs
Sources
Originally found and disclosed by Mencha Isajlovska of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2025-5927) Third-party advisory
- Packet Storm Security Exploit Entry Exploit / PoC
- Ksenia Security Vendor Homepage
- Third-party advisory