HomeSecurityGladinet hard-coded keys exploited for code execution

Exploiting Gladinet hard-coded keys for code execution

Huntress is warning of a new vulnerability in Gladinet's CentreStack and Triofox products that is actively being exploited and results from the use of hard-coded cryptographic keys . So far, it has affected nine organizations .

Gladinet hard-coded

"Malicious actors can potentially exploit this vulnerability to gain access to the web.config file, opening the door for deserialization and remote code execution," said security researcher Bryan Masters.

Gladinet's use of hard-coded cryptographic keys could allow malicious actors to decrypt or construct access tickets, which would allow them to gain access to sensitive files such as web.config, which can be exploited to achieve ViewState deserialization and remote code execution, the cybersecurity firm added.

See also: GitHub Action Secrets are no longer secure

At its core, the issue is based on a function called “GenerateSecKey()” present in “GladCtrl64.dll” and used to generate cryptographic keys, which are necessary to encrypt access tickets that contain authorization data (i.e., Username and Password) and allow access to the file system as a user (as long as the credentials are valid).

Because the GenerateSecKey() function returns the same 100-byte text strings and these strings are used to generate cryptographic keys, the keys never change and can be used to decrypt any ticket generated by the server or even to encrypt a ticket of the attacker's choosing.

This, in turn, opens the door to a scenario where it can be exploited to gain access to files containing valuable data (such as the web.config file) and obtain the machine key required for remote code execution via ViewState deserialization.

See also: Racks, sprawl, and the myth of redundant security

Exploiting Gladinet hard-coded keys for code execution
Exploiting Gladinet hard-coded keys for code execution

The attacks, according to Huntress, take the form of specially crafted URL requests to the “/storage/filesvr.dn” endpoint.

Attack attempts have been found to leave the Username and Password fields blank, causing the application to fall back to the IIS Application Pool Identity. The timestamp field in the access ticket, which refers to the time the ticket was created, is set to 9999, effectively creating a ticket that never expires and allowing malicious actors to reuse the URL indefinitely and download the server configuration.

As of December 10, up to nine organizations have been affected by this vulnerability. These organizations are in a wide range of sectors, including healthcare and technology. The attacks originate from the IP address 147.124.216[.]205 and attempt to combine a previously disclosed vulnerability in the same applications (CVE-2025-11371) with the new exploit to obtain themachine key from the web.config file.

“Once the attacker managed to obtain the keys, he performed a viewstate deserialization attack and then attempted to retrieve the execution output, which failed,” Huntress said.

See also: North Korean hackers exploit React2Shell to deploy EtherRAT

Gladinet: CentreStack and Triofox update for protection

Due to the active exploit, organizations using CentreStack and Triofox should update to the latest version, 16.12.10420.56791, released on December 8, 2025. Additionally, they are advised to scan their logs for the presence of the string “vghpI7EToZUDIZDdprSubL3mTZ2”, which is the encrypted representation of the web.config file path.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Exploiting Gladinet hard-coded keys for code execution

In case indicators of compromise (IoCs) are detected, it is imperative to machine key rotation through these steps:

1. On the CentreStack server, navigate to the CentreStack installation folder C:\Program Files (x86)\Gladinet Cloud Enterprise\root.

2. Create a backup of web.config.

3. Open IIS Manager

4. Go to Sites -> Default Web Site.

5. In the ASP.NET section, double-click Machine Key.

6. Click 'Generate Keys' in the right panel.

7. Click Apply to save it to root\web.config.

8. Restart IIS after repeating the same step for all worker nodes

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS