CVE-2025-15113

7.8

Ksenia Security · lares

Ksenia Security lares version 1.6 contains an unprotected endpoint vulnerability allowing authenticated attackers to upload binary files, potentially leading to arbitrary code execution.

Executive summary

An unprotected file upload vulnerability in Ksenia Security lares home automation systems allows authenticated attackers to achieve remote code execution by overwriting flash memory.

Vulnerability

This vulnerability involves an unprotected endpoint that permits authenticated attackers to upload MPFS File System binary images. By leveraging this flaw, an attacker can overwrite flash program memory, which enables the execution of arbitrary code on the underlying web server.

Business impact

Successful exploitation of this vulnerability grants an attacker complete control over the affected home automation system. This could lead to a total compromise of facility security, unauthorized access to sensitive data, and physical security risks. With a CVSS score of 7.8, this high-severity flaw represents a significant risk to operational integrity and system availability.

Remediation

Immediate Action: Contact Ksenia Security support immediately to determine if a firmware patch is available for your specific hardware revision and apply it.

Proactive Monitoring: Review system access logs for unauthorized file upload attempts or suspicious administrative activity targeting the web interface.

Compensating Controls: Restrict network access to the lares web management interface to trusted administrative IP addresses only, using a firewall or VPN, to prevent unauthorized access by potential attackers.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the Packet Storm Security advisory.

Analyst recommendation

This vulnerability poses a critical risk to the security and stability of the Ksenia Security lares platform. Administrators must prioritize the isolation of these devices from public networks until a vendor-supplied firmware update can be verified and applied to remediate the unsafe file upload functionality.

More Ksenia Security CVEs

Sources

Originally found and disclosed by Mencha Isajlovska of Zero Science Lab, per the CVE Program record.