HomeSecurityActive exploitation of vulnerability in Gladinet and TrioFox

Active vulnerability exploitation in Gladinet and TrioFox

Cybersecurity firm Huntress reported that it has observed active exploitation of an unpatched vulnerability affecting Gladinet products CentreStack and TrioFox.

Gladinet and TrioFox vulnerability

The zero-day, tracked as CVE-2025-11371 (CVSS score: 6.1), is a “local file inclusion” bug that allows the inadvertent disclosure of system. It affects all versions of the software prior to 16.7.10368.56560 (including this version).

See also: SnakeKeylogger steals sensitive data via emails

Huntress reported that it first detected the activity on September 27, 2025, revealing that three of its customers have been affected so far.

It is worth noting that both applications were previously affected by another vulnerability, CVE-2025-30406 (CVSS score: 9.0). This was a case of a hard-coded machine key that could allow a malicious user to perform remote code execution via a ViewState deserialization vulnerability. This vulnerability has been exploited by hackers.

Gladinet CentreStack – TrioFox: New dangerous vulnerability

Active vulnerability exploitation in Gladinet and TrioFox

According to Huntress, the new vulnerability, CVE-2025-11371, “allowed a malicious user to retrieve the machine key from the application Web.config file to perform remote code execution via the aforementioned ViewState deserialization vulnerability.” Additional details of the vulnerability have not been made public, due to active exploration and the absence of a patch.

See also: New Quishing attack targets Microsoft users

In one case investigated by the company, the affected version was newer than 16.4.10315.56368 and was not vulnerable to the CVE-2025-30406 vulnerability, indicating that attackers could exploit older versions and use the hard-coded machine key to execute code remotely via the ViewState deserialization vulnerability.

Active vulnerability exploitation in Gladinet and TrioFox

Temporary protection

In the meantime, users are advised to disable the “temp” handler within the Web.config file for UploadDownloadProxy located at “C:\Program Files (x86)\Gladinet Cloud Enterprise\UploadDownloadProxy\Web.config”.

See also: SonicWall: Hackers stole all customers' firewall configuration backup files

“This will impact some platform functionality. However, it will ensure that this vulnerability cannot be exploited until it is patched,” Huntress researchers Bryan Masters, James Maclachlan, Jai Minton, and John Hammond said.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS