Kseniasecurity develops the Lares physical access control platform and its embedded firmware, where reported vulnerabilities center on resource-handling and credential-management weaknesses such as file descriptor leaks, improper sphere isolation, and plaintext credential storage alongside web-layer issues including open redirects. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kseniasecurity over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15111CRITICAL Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploi | Dec 30, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-15114CRITICAL Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authenticatio | Dec 30, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-15113CRITICAL Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binar | Dec 30, 2025 | 9.3 | 30 | NO | NO |
CVE-2025-15112MEDIUM Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET param | Dec 30, 2025 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kseniasecurity.
Media articles that mention a CVE ID that affects a product developed by Kseniasecurity — matched by CVE ID, not by vendor name.