CVE-2025-15111: Kseniasecurity Lares Firmware
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.
Affected products
- Kseniasecurity Lares Firmware: version 1.6 only
Published 2025-12-30. Last modified 2026-06-17.