Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
History

Tue, 30 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
Title Ksenia Security Lares 4.0 Home Automation 1.6 URL Redirection Vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-30T22:41:46.247Z

Reserved: 2025-12-27T01:46:41.722Z

Link: CVE-2025-15112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-30T23:15:49.733

Modified: 2025-12-30T23:15:49.733

Link: CVE-2025-15112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.