CVE-2025-14611
9.5 CISA KEVGladinet · CentreStack and Triofox
Gladinet CentreStack and Triofox versions prior to 16.12.10420.56791 contain a hardcoded cryptographic vulnerability that allows unauthenticated attackers to perform local file inclusion.
Executive summary
This critical vulnerability in Gladinet CentreStack and Triofox is currently being exploited in the wild and enables unauthenticated attackers to achieve full system compromise.
Vulnerability
The software utilizes hardcoded values for its AES cryptographic implementation, which allows an unauthenticated attacker to supply specially crafted requests to achieve local file inclusion. This flaw can be chained with other vulnerabilities to facilitate unauthorized system access and full compromise.
Business impact
Successful exploitation poses a severe risk to organizational security, as it allows unauthenticated remote attackers to read sensitive configuration files and potentially execute arbitrary code. Given the CVSS score of 9.5 and evidence of active exploitation in the wild, this vulnerability presents an immediate threat to data confidentiality, integrity, and availability. Failure to remediate could result in complete system takeover and unauthorized access to protected enterprise data.
Remediation
Immediate Action: Update all instances of CentreStack and Triofox to version 16.12.10420.56791 or later immediately.
Proactive Monitoring: Review web server and application logs for anomalous traffic patterns, specifically looking for unusual GET or POST requests directed at endpoints that may indicate file inclusion attempts.
Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter and block requests containing suspicious patterns or known exploit signatures associated with this vulnerability while the update process is completed.
Exploitation status
Public Exploit Available: Yes: A Metasploit module and Nuclei template are publicly available.
Analyst recommendation
Due to the critical severity and confirmed active exploitation, immediate patching is required for all affected systems. Organizations should prioritize this update above other non-critical maintenance tasks to prevent potential data breaches and system-wide unauthorized access. Ensure all public-facing endpoints are protected and verify that the patch has been applied successfully across the entire environment.
More Gladinet CVEs
Sources
Originally found and disclosed by Bryan Masters, John Hammond, per the CVE Program record.