CVE-2025-15112

Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*

History

11 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-601

20 Feb 2026, 17:25

Type Values Removed Values Added
CWE CWE-601

19 Feb 2026, 20:25

Type Values Removed Values Added
Summary (en) Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain. (en) Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.

16 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 5.4

07 Jan 2026, 22:00

Type Values Removed Values Added
CPE cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*
First Time Kseniasecurity
Kseniasecurity lares
Kseniasecurity lares Firmware
References () https://packetstorm.news/files/id/190179/ - () https://packetstorm.news/files/id/190179/ - Third Party Advisory
References () https://www.kseniasecurity.com/ - () https://www.kseniasecurity.com/ - Product
References () https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-url-redirection-vulnerability - () https://www.vulncheck.com/advisories/ksenia-security-lares-home-automation-url-redirection-vulnerability - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php - Third Party Advisory

02 Jan 2026, 15:15

Type Values Removed Values Added
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5928.php -

30 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 23:15

Updated : 2026-03-11 20:16


NVD link : CVE-2025-15112

Mitre link : CVE-2025-15112

CVE.ORG link : CVE-2025-15112


JSON object : View

Products Affected

kseniasecurity

  • lares_firmware
  • lares
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')