CVE Vulnerabilities

CVE-2025-15111

Published: Dec 30, 2025 | Modified: Feb 19, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

Affected Software

NameVendorStart VersionEnd Version
Lares_firmwareKseniasecurity1.6 (including)1.6 (including)

References