Vulnerability record · CVE-2025-14611 · published 12 December 2025
CVE-2025-14611: Gladinet CentreStack and Triofox hardcoded AES key enables file inclusion
Gladinet · Centrestack
CentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints. A specially crafted unauthenticated request can trigger arbitrary local file inclusion, and the flaw can be chained with other vulnerabilities for full system compromise.
Description
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityIt is in CISA KEV with active exploitation, unauthenticated network reachability, and a high EPSS score, with a federal remediation deadline of 2026-01-05.
What it is
CentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints. A specially crafted unauthenticated request can trigger arbitrary local file inclusion, and the flaw can be chained with other vulnerabilities for full system compromise.
Impact
An unauthenticated attacker can read local files through crafted requests and, by chaining with other flaws, potentially achieve full system compromise.
Attack surface
Reachable over the network on public-facing endpoints with no authentication and no user interaction required, per the CVSS vector (AV:N/PR:N/UI:N). The description states the crafted request is unauthenticated.
Exploitation
Listed in CISA KEV with a 2025-12-15 addition and a 2026-01-05 due date, and a Huntress reference is tagged Exploit, indicating active exploitation. EPSS 30-day probability is 0.53302 (98.9th percentile).
What to do
- Upgrade CentreStack and Triofox to version 16.12.10420.56791 or later.
- If patching is not immediately possible, follow vendor mitigations or discontinue use of the exposed product per CISA BOD 22-01 guidance.
- Remove or restrict public exposure of CentreStack and Triofox endpoints until patched.
- Rotate any secrets or credentials that may have been exposed through file inclusion or chained exploitation.
Detection
- Hunt for crafted requests to CentreStack/Triofox endpoints that attempt local file inclusion or path traversal.
- Monitor for anomalous file reads or access to sensitive local files by the web service account.
- Review logs for exploitation attempts preceding other compromise activity, since the flaw is described as chaining with prior vulnerabilities.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-14611 to the Known Exploited Vulnerabilities catalog on 15 December 2025 as "Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 5 January 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.huntress.com/blog/active-exploitation-gladinet-centrestack-triofox-insecure-cryptography-vulnerability | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14611 | US Government Resource |
Track CVE-2025-14611 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-14611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.