Vulnerability record · CVE-2025-11371 · published 9 October 2025
CVE-2025-11371: Gladinet CentreStack and Triofox unauthenticated local file inclusion
Gladinet · Centrestack
CentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclosure of system files. The issue affects all versions prior to and including 16.7.10368.56560, and exploitation has been observed in the wild.
Description
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityUnauthenticated network-reachable file disclosure with confirmed in-the-wild exploitation, KEV listing and very high EPSS probability.
What it is
CentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclosure of system files. The issue affects all versions prior to and including 16.7.10368.56560, and exploitation has been observed in the wild.
Impact
An unauthenticated attacker can read arbitrary system files from the server, exposing configuration data, credentials or other sensitive content that can support further intrusion.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is present in the default installation and configuration, so exposed instances are directly at risk.
Exploitation
Exploitation has been observed in the wild, the CVE was added to CISA KEV on 2025-11-04, and EPSS gives a 30-day probability of 0.92137 (99.8th percentile). A public third-party advisory is tagged as containing an exploit.
What to do
- Upgrade CentreStack and Triofox to a version later than 16.7.10368.56560 per the vendor release notes.
- If patching is not immediately possible, apply the vendor's mitigations or discontinue use of the product, following CISA BOD 22-01 guidance for cloud services.
- Remove or restrict internet exposure of CentreStack and Triofox management interfaces until the upgrade is complete.
- Review file system and web server logs for anomalous access to system files from unauthenticated requests.
- Rotate credentials and secrets that may have been stored in files readable through the inclusion flaw.
Detection
- Hunt web and application logs for requests containing path traversal or file inclusion patterns against CentreStack and Triofox endpoints.
- Monitor for unauthenticated access to known sensitive system file paths from external source IPs.
- Alert on unexpected outbound connections or new processes spawned by the CentreStack or Triofox service following file reads.
- Correlate file access events on the host with web requests to identify reads of files outside the application directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-11371 to the Known Exploited Vulnerabilities catalog on 4 November 2025 as "Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 November 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw | ExploitThird Party Advisory |
| https://www.centrestack.com/p/gce_latest_release.html | Release Notes |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-11371 | US Government Resource |
Track CVE-2025-11371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-11371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.