CVE-2025-11371
9.5 CISA KEVGladinet · CentreStack and Triofox
An unauthenticated Local File Inclusion (LFI) vulnerability in Gladinet CentreStack and Triofox allows attackers to disclose sensitive system files, facilitating further exploitation.
Executive summary
This critical vulnerability allows unauthenticated attackers to read arbitrary files on Gladinet CentreStack and Triofox servers and is currently being actively exploited in the wild.
Vulnerability
This is an unauthenticated Local File Inclusion (LFI) vulnerability that permits attackers to access sensitive system files. By retrieving configuration files, such as the Web.config file, an attacker can obtain the ASP.NET machine key, which acts as a precursor for additional attacks.
Business impact
The exploitation of this vulnerability carries a CVSS score of 9.5, reflecting its critical severity. Successful compromise allows an attacker to steal sensitive credentials and system keys, which can be chained with other vulnerabilities to achieve remote code execution. This poses a catastrophic risk to data confidentiality, system integrity, and overall organizational security posture.
Remediation
Immediate Action: Update all instances of Gladinet CentreStack and Triofox to version 16.12.10420.56791 or newer immediately.
Proactive Monitoring: Review system logs for anomalous file access patterns or unexpected requests to configuration files, particularly those originating from unauthorized external IP addresses.
Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter and block suspicious directory traversal attempts or requests targeting sensitive configuration files.
Exploitation status
Public Exploit Available: Yes, a Metasploit module and public proof-of-concept repositories exist.
Analyst recommendation
Given the critical severity, confirmed active exploitation, and the availability of public exploits, organizations must prioritize patching this vulnerability immediately. Failure to apply the vendor-provided update leaves the environment highly susceptible to complete system compromise. Ensure that all internet-facing instances are secured without delay.
More Gladinet CVEs
Sources
Originally found and disclosed by Bryan Masters, James Maclachlan, Jai Minton, per the CVE Program record.