CVE-2025-11371

9.5 CISA KEV

Gladinet · CentreStack and Triofox

An unauthenticated Local File Inclusion (LFI) vulnerability in Gladinet CentreStack and Triofox allows attackers to disclose sensitive system files, facilitating further exploitation.

Executive summary

This critical vulnerability allows unauthenticated attackers to read arbitrary files on Gladinet CentreStack and Triofox servers and is currently being actively exploited in the wild.

Vulnerability

This is an unauthenticated Local File Inclusion (LFI) vulnerability that permits attackers to access sensitive system files. By retrieving configuration files, such as the Web.config file, an attacker can obtain the ASP.NET machine key, which acts as a precursor for additional attacks.

Business impact

The exploitation of this vulnerability carries a CVSS score of 9.5, reflecting its critical severity. Successful compromise allows an attacker to steal sensitive credentials and system keys, which can be chained with other vulnerabilities to achieve remote code execution. This poses a catastrophic risk to data confidentiality, system integrity, and overall organizational security posture.

Remediation

Immediate Action: Update all instances of Gladinet CentreStack and Triofox to version 16.12.10420.56791 or newer immediately.

Proactive Monitoring: Review system logs for anomalous file access patterns or unexpected requests to configuration files, particularly those originating from unauthorized external IP addresses.

Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter and block suspicious directory traversal attempts or requests targeting sensitive configuration files.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and public proof-of-concept repositories exist.

Analyst recommendation

Given the critical severity, confirmed active exploitation, and the availability of public exploits, organizations must prioritize patching this vulnerability immediately. Failure to apply the vendor-provided update leaves the environment highly susceptible to complete system compromise. Ensure that all internet-facing instances are secured without delay.

More Gladinet CVEs

Sources

Originally found and disclosed by Bryan Masters, James Maclachlan, Jai Minton, per the CVE Program record.