CVE-2025-15113

Source
https://cve.org/CVERecord?id=CVE-2025-15113
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15113.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15113
Published
2025-12-30T23:15:49.913Z
Modified
2026-03-15T22:50:22.442739Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the home automation system's web server.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15113.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6"
            }
        ]
    }
]