CVE-2025-15113
7.8Ksenia Security · lares
Ksenia Security lares version 1.6 contains an unprotected endpoint vulnerability allowing authenticated attackers to upload binary files, potentially leading to arbitrary code execution.
Executive summary
An unprotected file upload vulnerability in Ksenia Security lares home automation systems allows authenticated attackers to achieve remote code execution by overwriting flash memory.
Vulnerability
This vulnerability involves an unprotected endpoint that permits authenticated attackers to upload MPFS File System binary images. By leveraging this flaw, an attacker can overwrite flash program memory, which enables the execution of arbitrary code on the underlying web server.
Business impact
Successful exploitation of this vulnerability grants an attacker complete control over the affected home automation system. This could lead to a total compromise of facility security, unauthorized access to sensitive data, and physical security risks. With a CVSS score of 7.8, this high-severity flaw represents a significant risk to operational integrity and system availability.
Remediation
Immediate Action: Contact Ksenia Security support immediately to determine if a firmware patch is available for your specific hardware revision and apply it.
Proactive Monitoring: Review system access logs for unauthorized file upload attempts or suspicious administrative activity targeting the web interface.
Compensating Controls: Restrict network access to the lares web management interface to trusted administrative IP addresses only, using a firewall or VPN, to prevent unauthorized access by potential attackers.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the Packet Storm Security advisory.
Analyst recommendation
This vulnerability poses a critical risk to the security and stability of the Ksenia Security lares platform. Administrators must prioritize the isolation of these devices from public networks until a vendor-supplied firmware update can be verified and applied to remediate the unsafe file upload functionality.
More Ksenia Security CVEs
Sources
Originally found and disclosed by Mencha Isajlovska of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2025-5930) Third-party advisory
- Ksenia Security Vendor Homepage
- Packet Storm Security Exploit Exploit / PoC
- Third-party advisory