Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave Security Patch Release

Gladinet machine-key exploitation chain

Updated 11.12.2025 23:49
Case score 69
Members 5 First seen 10.10.2025 12:34 Latest activity 11.12.2025 23:49

Overview

Attackers are exploiting **Gladinet CentreStack** and **Triofox** by abusing hardcoded AES keys and access-ticket handling to recover `Web.config`, steal the ASP.NET machine key, and reach **remote code execution**. Huntress said the activity had already targeted **at least nine organizations**, used crafted requests from `147.124.216[.]205`, and relied on `/storage/filesvr.dn` traffic to forge or decrypt tickets. Gladinet released **CentreStack 16.10.10408.56683** for **CVE-2025-11371** and told administrators to install it. If upgrading is not possible, the temporary mitigation is to disable the temp handler in `UploadDownloadProxy/Web.config`, which can affect some platform functionality.
Latest development Open development history 4 earlier developments Public disclosure of active CVE-2025-11371 exploitation in Gladinet CentreStack and TrioFox Huntress disclosed active in-the-wild exploitation of CVE-2025-11371 in Gladinet CentreStack and TrioFox, describing the flaw as an unauthenticated local file inclusion bug that affects versions through 16.7.10368.56560. Huntress also advised disabling the temp handler in UploadDownloadProxy/Web.config until the vulnerability is patched.
  1. Earlier development

    Gladinet discloses active exploitation of CentreStack and Triofox flaw

    Gladinet notified customers about an undocumented cryptographic vulnerability in CentreStack and Triofox, said the issue was being exploited in the wild, and shared IoCs that Huntress used to trace hardcoded AES keys in GladCtrl64.dll, forged Access Tickets through filesvr.dn, and a path toward remote code execution and the vghpI7EToZUDIZDdprSubL3mTZ2 indicator.

  2. Earlier development

    Gladinet CentreStack and Triofox active exploitation wave

    The early wave centers on repeated forged-ticket requests from **147.124.216[.]205** against **Gladinet CentreStack** and **Triofox**, with the aim of reaching **web.config** through **/storage/filesvr.dn**.

  3. Earlier development

    Huntress observes active CVE-2025-11371 exploitation

    Researchers at Huntress detected active exploitation of CVE-2025-11371 in Gladinet CentreStack and Triofox on September 27, when a threat actor used a Local File Inclusion flaw in the default installation to read Web.config, extract the machine key, and chain CVE-2025-30406 for remote code execution.

  4. Earlier development

    First detection of CVE-2025-11371 exploitation against Gladinet CentreStack and TrioFox

    Huntress first detected active in-the-wild exploitation of CVE-2025-11371 affecting Gladinet CentreStack and TrioFox on September 27, 2025, and found that three customers had been impacted. The activity involved an unauthenticated local file inclusion flaw that could disclose system files and support a chain to remote code execution through the previously known CVE-2025-30406 path.

Signals

Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Data exposure

Tooling context

1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Gladinet CentreStack and Triofox hardcoded AES keys RCE flaw
Updated 11.12.2025 23:49 Lead Contribution 64
Exploitation Active Exploitation Data Type Passwords Data Type Usernames Patch Patch Available

A new **Gladinet CentreStack** and **Triofox** vulnerability in the products' custom AES implementation is being **actively exploited** to recover **hardcoded cryptographic keys** and enable **remote code execution**. **Gladinet** told customers to upgrade and rotate machine keys, while researchers said the abuse had already targeted **at least nine organizations**. The flaw affects secure remote file access and sharing systems, making exposed deployments a direct takeover risk.

Exploitation Wave Gladinet CentreStack and Triofox active exploitation wave
Updated 11.12.2025 07:56 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

Active exploitation of **Gladinet CentreStack** and **Triofox** has affected **at least nine organizations**, creating risk of unauthorized access and follow-on **remote code execution**. Attack traffic has been observed from **147.124.216[.]205** using crafted requests to **/storage/filesvr.dn** and forged access tickets. The activity also appears to chain the new abuse with **CVE-2025-11371** to reach **web.config** and obtain the machine key.

Vulnerability Gladinet CentreStack and TrioFox actively exploited unauthenticated LFI remote code execution flaw (multiple vulnerabilities)
Updated 10.10.2025 12:34 Scoring Support Contribution 2
Exploitation Active Exploitation Data Type Source Code CVSS 9.8 Critical Data Status Exposed/Unsecured

**Gladinet CentreStack** is now patched for **CVE-2025-11371**, an **unauthenticated local file inclusion** flaw that threat actors have used as a **zero-day** since **late September**. The bug let attackers read `Web.config`, extract the ASP.NET machine key, and chain into **CVE-2025-30406** for **remote code execution** on affected deployments. Gladinet says the fix is available in **CentreStack version 16.10.10408.56683**, and administrators are strongly recommended to install it. If upgrading is not possible, the interim mitigation is to disable the **temp handler** in `UploadDownloadProxy/Web.config`.

Security Patch Release CentreStack security update for CVE-2025-11371
Updated 16.10.2025 18:11 Context
Exploitation Active Exploitation Urgency High Patch Patch Available

**Gladinet** released a **security update** for **CentreStack** to fix **CVE-2025-11371**, a **zero-day** local file inclusion flaw affecting business file-sharing deployments. The issue had been abused since **late September** and could expose **Web.config** on fully patched systems, letting attackers extract the **ASP.NET machine key**. The new build, **version 16.10.10408.56683**, is available now, and administrators are **strongly recommended** to install it. If upgrading is not possible, a temporary mitigation is to disable the **temp handler** in **Web.config** for the **UploadDownloadProxy** component.

Advisory/Mitigation Gladinet CentreStack and Triofox workaround for CVE-2025-11371
Updated 10.10.2025 22:08 Context
Exploitation Active Exploitation Urgency High

**CentreStack** and **Triofox** are affected by **CVE-2025-11371**, a **local file inclusion zero-day** that threat actors have **abused since late September** to read **Web.config**, extract the ASP.NET machine key, and chain into **CVE-2025-30406** for **remote code execution**. **Gladinet** has released **version 16.10.10408.56683** to fix the issue and previously advised a **temporary workaround** for customers who cannot upgrade. The workaround disables the **temp handler** in **Web.config** for the **UploadDownloadProxy** component, but it can **impact some functionality**.