HomeSecurityCISA adds Gladinet and CWP vulnerabilities to KEV List

CISA adds Gladinet and CWP vulnerabilities to KEV List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities, affecting Gladinet and Control Web Panel (CWP), to the list of Known Exploitable Vulnerabilities (KEV).

CISA adds Gladinet vulnerabilities

The vulnerabilities mentioned are:

CVE-2025-11371 (CVSS score: 7.5): A vulnerability in files or directories accessible by external parties in Gladinet CentreStack and Triofox. It could lead to unintentional disclosure of system.

CVE-2025-48703 (CVSS score: 9.0): An OS command injection in the Control Web Panel (formerly known as CentOS Web Panel). It leads to unauthorized remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request.

See also: Vulnerability in React Native CLI puts millions of developers at risk

The addition of the Gladinet vulnerability to the CISA KEV List comes just weeks after cybersecurity firm Huntress active exploitation attempts. Unknown threat actors were exploiting the vulnerability to execute reconnaissance commands (e.g., ipconfig /all) passed in the form of a Base64 encoded payload.

CISA adds Gladinet and CWP vulnerabilities to KEV List

However, there are still no public reports of how the CWP vulnerability, CVE-2025-48703, is being exploited. Technical details of the vulnerability were shared by security researcher Maxime Rinaudo in June 2025, shortly after the patch was released in version 0.9.8.1205 (after a responsible disclosure on May 13). Rinaudo said: “It allows a remote attacker, knowing a valid username on a CWP installation, to execute pre-authenticated arbitrary commands on the server.”

See also: Warning! Serious vulnerabilities in Microsoft Teams

Due to the active exploitation, federal FCEB agencies are required to implement the necessary fixes by November 25, 2025 to secure their networks.

CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.

See also: Android: Critical 0-click vulnerability allows RCE attacks

CISA adds Gladinet and CWP vulnerabilities to KEV List

It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications. Overall, CISA's role is vital to protecting the digital infrastructure of the United States and other regions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS