HomeSecurityCentreStack vulnerability used to compromise file sharing servers

CentreStack vulnerability used to compromise file sharing servers

Since last month, hackers have been exploiting a zero-day vulnerability in Gladinet CentreStack to compromise storage servers.

CentreStack vulnerability

Gladinet CentreStack is an enterprise file sharing and access platform. It transforms on-premise file servers into secure cloud-based file systems that support remote access to internal file shares, file synchronization and sharing, multi-tenant deployments, and Active Directory integration.

The vulnerability, which is tracked as CVE-2025-30406, affects Gladinet CentreStack versions up to 16.1.10296.56315.

See also: Critical FortiSwitch vulnerability allows admin passwords to be changed remotely

The issue stems from the use of a hardcoded machineKey in the CentreStack portal configuration. If an attacker knows this key, they can create a malicious serialized payload that the server will trust and execute.

A vulnerable key (without proper protection) protects ASP.NET ViewState, which, if tampered with, allows attackers to bypass integrity checks , inject arbitrary serialized objects, and ultimately execute code on the server.

Protection against the Gladinet CentreStack vulnerability

Gladinet released a fix on April 3, 2025 in versions: 16.4.10315.56368, 16.3.4763.56357 (Windows) and 15.12.434 (macOS).

See also: Hackers steal AWS credentials via SSRF flaws

All users are urged to upgrade to the latest version as soon as possible or rotate the 'machineKey' in both root\web. config and portal\web. config.

Since the vulnerability is already being used by hackers, immediate protective measures are necessary.

CentreStack vulnerability used to compromise file sharing servers
CentreStack vulnerability used to compromise file sharing servers

Those performing machineKey rotation in their environment should ensure consistency across nodes in multi-server deployments to avoid operational issues. They should also restart IIS services after changes for the protection steps to take effect.

CISA has added CVE-2025-30406 to its list of Known Exploitable Vulnerabilities. The US agency has given state and federal agencies until April 29, 2025, to fix the vulnerability.

See also: Windows Remote Desktop vulnerability allows RCE execution

The fact that the exploit began last month means that some organizations may not yet have realized they have been breached, since these attacks are often “silent.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also, the exploitation began before the vulnerability was even patched (i.e. as a zero-day). The time between the discovery of a zero-day and the release of a patch is critical. These attacks are a prime example of why proactive security, patch management , and monitoring for unusual activity are essential today.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS