CVE-2025-12480
9.5 CISA KEVGladinet · Triofox
Gladinet Triofox versions prior to 16.7.10368.56560 contain an improper access control vulnerability that allows unauthenticated access to sensitive initial setup pages.
Executive summary
A critical access control vulnerability in Gladinet Triofox is currently being exploited in the wild, posing a severe risk of unauthorized configuration and system compromise.
Vulnerability
This flaw involves improper access control (CWE-284) that allows unauthenticated attackers to access initial setup pages even after the deployment has been finalized. Because the vulnerability is remotely exploitable without authentication, it allows for unauthorized manipulation of administrative settings.
Business impact
The ability for an unauthenticated actor to access setup pages presents an extreme risk to organizational security, potentially leading to unauthorized administrative control over the file access gateway. Given the CVSS score of 9.5, this vulnerability is critical, as it provides a pathway for attackers to intercept data or reconfigure authentication settings. Successful exploitation could result in full loss of confidentiality and integrity for the affected environment.
Remediation
Immediate Action: Update the Triofox software to version 16.7.10368.56560 or later immediately to restrict access to the setup interface.
Proactive Monitoring: Monitor server access logs for anomalous requests directed toward the initial setup endpoints or unexpected administrative configuration changes.
Compensating Controls: Implement strict network perimeter controls or a Web Application Firewall (WAF) to block external access to the setup pages until the patch can be applied.
Exploitation status
Public Exploit Available: No (A Nuclei detection template exists, but no weaponized exploit or public proof-of-concept is documented.)
Analyst recommendation
Due to the confirmed active exploitation and the critical nature of this flaw, immediate patching is required. Organizations must prioritize updating all instances of Triofox to the current secure version to prevent unauthorized access and potential system takeover.
More Gladinet CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented version 16.7.10368.56560 per CVE record
Sources
Originally found and disclosed by Stallone D’Souza, Mandiant, per the CVE Program record.