Ksenia Security Lares 4.0 Home Automation version 1.6...
Critical severity
Unreviewed
Published
Dec 31, 2025
to the GitHub Advisory Database
•
Updated Jan 13, 2026
Description
Published by the National Vulnerability Database
Dec 30, 2025
Published to the GitHub Advisory Database
Dec 31, 2025
Last updated
Jan 13, 2026
Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.
References