5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Description
Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
Basic Information
ID
CVE-2025-15112
Source
VulnCheck
Published
Dec 30, 2025 at 22:41
Affected Product
Vendor
Ksenia Security S.p.A.
Product
Ksenia Security Lares 4.0 Home Automation
Version
1.6
Affected Versions
Ksenia Security S.p.A. Ksenia Security Lares 4.0 Home Automation 1.6
Ksenia Security S.p.A. Ksenia Security Lares 4.0 Home Automation 1.0.0.15
Ksenia Security S.p.A. Ksenia Security Lares 4.0 Home Automation 1.0.0.15