Gladinet Centrestack And Triofox vulnerabilities
2 known vulnerabilities affecting gladinet/centrestack_and_triofox.
Total CVEs
2
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2025-11371P1HIGHCVSS 7.5KEVPoCRansomware≤ 16.7.10368.565602025-10-09
CVE-2025-11371 [HIGH] CWE-552 CVE-2025-11371: In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unaut
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.
This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.1036
nvd
CVE-2025-14611P1CRITICALCVSS 9.8KEVPoCfixed in 16.12.10420.567912025-12-12
CVE-2025-14611 [CRITICAL] CWE-798 CVE-2025-14611: Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for
nvd