CVE-2025-15111
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.
CRITICAL · CVSS 9.8
EPSS 0.00026
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0