← Vulnerability feed

Vulnerability record · CVE-2025-11371 · published 9 October 2025

CVE-2025-11371: Gladinet CentreStack and Triofox unauthenticated local file inclusion

Gladinet · Centrestack

CentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclosure of system files. The issue affects all versions prior to and including 16.7.10368.56560, and exploitation has been observed in the wild.

7.5 CVSS 3.1 High CISA KEV since 4 Nov 2025 EPSS 92% · top 0.2% CWE-552 · CWE-552
7.5CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable file disclosure with confirmed in-the-wild exploitation, KEV listing and very high EPSS probability.

What it is

CentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclosure of system files. The issue affects all versions prior to and including 16.7.10368.56560, and exploitation has been observed in the wild.

Impact

An unauthenticated attacker can read arbitrary system files from the server, exposing configuration data, credentials or other sensitive content that can support further intrusion.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is present in the default installation and configuration, so exposed instances are directly at risk.

Exploitation

Exploitation has been observed in the wild, the CVE was added to CISA KEV on 2025-11-04, and EPSS gives a 30-day probability of 0.92137 (99.8th percentile). A public third-party advisory is tagged as containing an exploit.

What to do

  • Upgrade CentreStack and Triofox to a version later than 16.7.10368.56560 per the vendor release notes.
  • If patching is not immediately possible, apply the vendor's mitigations or discontinue use of the product, following CISA BOD 22-01 guidance for cloud services.
  • Remove or restrict internet exposure of CentreStack and Triofox management interfaces until the upgrade is complete.
  • Review file system and web server logs for anomalous access to system files from unauthenticated requests.
  • Rotate credentials and secrets that may have been stored in files readable through the inclusion flaw.

Detection

  • Hunt web and application logs for requests containing path traversal or file inclusion patterns against CentreStack and Triofox endpoints.
  • Monitor for unauthenticated access to known sensitive system file paths from external source IPs.
  • Alert on unexpected outbound connections or new processes spawned by the CentreStack or Triofox service following file reads.
  • Correlate file access events on the host with web requests to identify reads of files outside the application directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-11371 to the Known Exploited Vulnerabilities catalog on 4 November 2025 as "Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 November 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-11371 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-30406Gladinet CentreStack hardcoded machineKey deserialization RCEGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) uses a hardcoded machineKey in the portal's web.config, allowing deserializ…KEVEPSS 94%analysed9.1CVE-2025-12480Gladinet Triofox improper access control exposes setup pagesTriofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Becaus…KEVEPSS 95%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed9.8CVE-2023-26829Gladinet centrestack incorrect authorization vulnerabilityAn authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new …EPSS 1.2%7.2CVE-2023-26830Gladinet centrestack unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticat…EPSS 1.1%4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed7.5CVE-2020-17519Apache Flink JobManager REST interface arbitrary file readA change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to f…KEVEPSS 98%analysed7.8CVE-2017-16651Roundcube Webmail file disclosure via attachment pluginRoundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows an authenticated user to read arbitrary files on the host filesyst…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2025-11371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.