Vulnerability record · CVE-2025-12480 · published 10 November 2025
CVE-2025-12480: Gladinet Triofox improper access control exposes setup pages
Gladinet · Triofox
Triofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Because those pages are unauthenticated and network reachable, an attacker can reach configuration functionality that should be closed off, and the flaw is already in CISA KEV with a very high EPSS score.
Description
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityUnauthenticated network-reachable access control bypass with CVSS 9.1, CISA KEV listing, and EPSS above 0.90 makes this an urgent patch-or-isolate case.
What it is
Triofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Because those pages are unauthenticated and network reachable, an attacker can reach configuration functionality that should be closed off, and the flaw is already in CISA KEV with a very high EPSS score.
Impact
An attacker gains unauthenticated access to setup and configuration pages, which can lead to changing or hijacking instance settings and potentially full compromise of confidentiality and integrity. Availability is not scored as affected by the CVSS vector.
Attack surface
Reachable over the network via HTTP(S) with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed or internally reachable Triofox instance running a version before 16.7.10368.56560 is in scope.
Exploitation
Listed in CISA KEV on 2025-11-12 with a remediation due date of 2025-12-03, and a Google/Mandiant reference is tagged as an exploit source. EPSS 30-day probability is 0.90532 (99.8th percentile), indicating active exploitation is expected.
What to do
- Upgrade Triofox to 16.7.10368.56560 or later per the vendor release history.
- If immediate patching is not possible, remove Triofox from internet exposure or discontinue use, as directed by the CISA KEV required action.
- Restrict network access to the Triofox management and setup endpoints to trusted administrative networks only.
- Review Triofox configuration and accounts for unauthorized changes made through setup pages, and rotate any credentials or keys stored there.
- Track the CISA KEV due date of 2025-12-03 to confirm remediation is completed.
Detection
- Hunt web logs for requests to Triofox initial setup or installation paths from unauthenticated or unexpected source IPs.
- Alert on access to setup pages after the instance has completed initial configuration.
- Monitor for configuration changes, new administrative accounts, or unexpected outbound connections from the Triofox host.
- Correlate Triofox access logs with the known exploitation activity described in the Google Threat Intelligence and Mandiant references.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-12480 to the Known Exploited Vulnerabilities catalog on 12 November 2025 as "Gladinet Triofox Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.triofox.com/releases_history/ | Release Notes |
| https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 | ExploitThird Party Advisory |
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md | Third Party Advisory |
| https://www.triofox.com/ | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 | US Government Resource |
Track CVE-2025-12480 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-12480), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.