Cybersecurity firm Huntress reported that it has observed active exploitation of an unpatched vulnerability affecting Gladinet products CentreStack and TrioFox.

The zero-day, tracked as CVE-2025-11371 (CVSS score: 6.1), is a “local file inclusion” bug that allows the inadvertent disclosure of system. It affects all versions of the software prior to 16.7.10368.56560 (including this version).
See also: SnakeKeylogger steals sensitive data via emails
Huntress reported that it first detected the activity on September 27, 2025, revealing that three of its customers have been affected so far.
It is worth noting that both applications were previously affected by another vulnerability, CVE-2025-30406 (CVSS score: 9.0). This was a case of a hard-coded machine key that could allow a malicious user to perform remote code execution via a ViewState deserialization vulnerability. This vulnerability has been exploited by hackers.
Gladinet CentreStack – TrioFox: New dangerous vulnerability

According to Huntress, the new vulnerability, CVE-2025-11371, “allowed a malicious user to retrieve the machine key from the application Web.config file to perform remote code execution via the aforementioned ViewState deserialization vulnerability.” Additional details of the vulnerability have not been made public, due to active exploration and the absence of a patch.
See also: New Quishing attack targets Microsoft users
In one case investigated by the company, the affected version was newer than 16.4.10315.56368 and was not vulnerable to the CVE-2025-30406 vulnerability, indicating that attackers could exploit older versions and use the hard-coded machine key to execute code remotely via the ViewState deserialization vulnerability.

Temporary protection
In the meantime, users are advised to disable the “temp” handler within the Web.config file for UploadDownloadProxy located at “C:\Program Files (x86)\Gladinet Cloud Enterprise\UploadDownloadProxy\Web.config”.
See also: SonicWall: Hackers stole all customers' firewall configuration backup files
“This will impact some platform functionality. However, it will ensure that this vulnerability cannot be exploited until it is patched,” Huntress researchers Bryan Masters, James Maclachlan, Jai Minton, and John Hammond said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
