← Vulnerability feed

Vulnerability record · CVE-2025-14611 · published 12 December 2025

CVE-2025-14611: Gladinet CentreStack and Triofox hardcoded AES key enables file inclusion

Gladinet · Centrestack

CentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints. A specially crafted unauthenticated request can trigger arbitrary local file inclusion, and the flaw can be chained with other vulnerabilities for full system compromise.

7.1 CVSS 4.0 High CISA KEV since 15 Dec 2025 EPSS 53% · top 1.0% CWE-798 · Hard-coded credentials
7.1CVSS 4.0 base score
53%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with active exploitation, unauthenticated network reachability, and a high EPSS score, with a federal remediation deadline of 2026-01-05.

What it is

CentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints. A specially crafted unauthenticated request can trigger arbitrary local file inclusion, and the flaw can be chained with other vulnerabilities for full system compromise.

Impact

An unauthenticated attacker can read local files through crafted requests and, by chaining with other flaws, potentially achieve full system compromise.

Attack surface

Reachable over the network on public-facing endpoints with no authentication and no user interaction required, per the CVSS vector (AV:N/PR:N/UI:N). The description states the crafted request is unauthenticated.

Exploitation

Listed in CISA KEV with a 2025-12-15 addition and a 2026-01-05 due date, and a Huntress reference is tagged Exploit, indicating active exploitation. EPSS 30-day probability is 0.53302 (98.9th percentile).

What to do

  • Upgrade CentreStack and Triofox to version 16.12.10420.56791 or later.
  • If patching is not immediately possible, follow vendor mitigations or discontinue use of the exposed product per CISA BOD 22-01 guidance.
  • Remove or restrict public exposure of CentreStack and Triofox endpoints until patched.
  • Rotate any secrets or credentials that may have been exposed through file inclusion or chained exploitation.

Detection

  • Hunt for crafted requests to CentreStack/Triofox endpoints that attempt local file inclusion or path traversal.
  • Monitor for anomalous file reads or access to sensitive local files by the web service account.
  • Review logs for exploitation attempts preceding other compromise activity, since the flaw is described as chaining with prior vulnerabilities.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-14611 to the Known Exploited Vulnerabilities catalog on 15 December 2025 as "Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 5 January 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-14611 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-30406Gladinet CentreStack hardcoded machineKey deserialization RCEGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) uses a hardcoded machineKey in the portal's web.config, allowing deserializ…KEVEPSS 94%analysed9.1CVE-2025-12480Gladinet Triofox improper access control exposes setup pagesTriofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Becaus…KEVEPSS 95%analysed7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed9.8CVE-2023-26829Gladinet centrestack incorrect authorization vulnerabilityAn authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new …EPSS 1.2%7.2CVE-2023-26830Gladinet centrestack unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticat…EPSS 1.1%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed

Source: NIST National Vulnerability Database (record CVE-2025-14611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.