← Vulnerability feed

Vulnerability record · CVE-2025-12480 · published 10 November 2025

CVE-2025-12480: Gladinet Triofox improper access control exposes setup pages

Gladinet · Triofox

Triofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Because those pages are unauthenticated and network reachable, an attacker can reach configuration functionality that should be closed off, and the flaw is already in CISA KEV with a very high EPSS score.

9.1 CVSS 3.1 Critical CISA KEV since 12 Nov 2025 EPSS 95% · top 0.1% CWE-284 · Improper access control
9.1CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable access control bypass with CVSS 9.1, CISA KEV listing, and EPSS above 0.90 makes this an urgent patch-or-isolate case.

What it is

Triofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Because those pages are unauthenticated and network reachable, an attacker can reach configuration functionality that should be closed off, and the flaw is already in CISA KEV with a very high EPSS score.

Impact

An attacker gains unauthenticated access to setup and configuration pages, which can lead to changing or hijacking instance settings and potentially full compromise of confidentiality and integrity. Availability is not scored as affected by the CVSS vector.

Attack surface

Reachable over the network via HTTP(S) with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed or internally reachable Triofox instance running a version before 16.7.10368.56560 is in scope.

Exploitation

Listed in CISA KEV on 2025-11-12 with a remediation due date of 2025-12-03, and a Google/Mandiant reference is tagged as an exploit source. EPSS 30-day probability is 0.90532 (99.8th percentile), indicating active exploitation is expected.

What to do

  • Upgrade Triofox to 16.7.10368.56560 or later per the vendor release history.
  • If immediate patching is not possible, remove Triofox from internet exposure or discontinue use, as directed by the CISA KEV required action.
  • Restrict network access to the Triofox management and setup endpoints to trusted administrative networks only.
  • Review Triofox configuration and accounts for unauthorized changes made through setup pages, and rotate any credentials or keys stored there.
  • Track the CISA KEV due date of 2025-12-03 to confirm remediation is completed.

Detection

  • Hunt web logs for requests to Triofox initial setup or installation paths from unauthenticated or unexpected source IPs.
  • Alert on access to setup pages after the instance has completed initial configuration.
  • Monitor for configuration changes, new administrative accounts, or unexpected outbound connections from the Triofox host.
  • Correlate Triofox access logs with the known exploitation activity described in the Google Threat Intelligence and Mandiant references.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-12480 to the Known Exploited Vulnerabilities catalog on 12 November 2025 as "Gladinet Triofox Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-12480 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-48907JCE editor for Joomla allows unauthenticated profile creation and PHP uploadThe JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. Thi…KEVEPSS 16%analysed9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2025-12480), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.