Gladinet machine-key exploitation chain
Case score 69
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 69
- Main story score
- 64
- Related evidence lift
- +5 / 20
- Contributing updates
- 2
- Context updates
- 2
- Vulnerability Defines the hardcoded-key abuse path that lets attackers decrypt or forge access tickets and move toward remote code execution. main
- Advisory Mitigation Adds the temporary mitigation guidance to disable the temp handler in `UploadDownloadProxy/Web.config`. context
- Security Patch Release Supplies patch context for CVE-2025-11371 and the temporary handler workaround. context
- Vulnerability Shows the local file inclusion path that exposes `Web.config` and supplies the machine key used in the follow-on chain. contributes
Overview
Latest development Open development history Public disclosure of active CVE-2025-11371 exploitation in Gladinet CentreStack and TrioFox Huntress disclosed active in-the-wild exploitation of CVE-2025-11371 in Gladinet CentreStack and TrioFox, describing the flaw as an unauthenticated local file inclusion bug that affects versions through 16.7.10368.56560. Huntress also advised disabling the temp handler in UploadDownloadProxy/Web.config until the vulnerability is patched.
-
Gladinet discloses active exploitation of CentreStack and Triofox flaw
Gladinet notified customers about an undocumented cryptographic vulnerability in CentreStack and Triofox, said the issue was being exploited in the wild, and shared IoCs that Huntress used to trace hardcoded AES keys in GladCtrl64.dll, forged Access Tickets through filesvr.dn, and a path toward remote code execution and the vghpI7EToZUDIZDdprSubL3mTZ2 indicator.
-
Gladinet CentreStack and Triofox active exploitation wave
The early wave centers on repeated forged-ticket requests from **147.124.216[.]205** against **Gladinet CentreStack** and **Triofox**, with the aim of reaching **web.config** through **/storage/filesvr.dn**.
-
Huntress observes active CVE-2025-11371 exploitation
Researchers at Huntress detected active exploitation of CVE-2025-11371 in Gladinet CentreStack and Triofox on September 27, when a threat actor used a Local File Inclusion flaw in the default installation to read Web.config, extract the machine key, and chain CVE-2025-30406 for remote code execution.
-
First detection of CVE-2025-11371 exploitation against Gladinet CentreStack and TrioFox
Huntress first detected active in-the-wild exploitation of CVE-2025-11371 affecting Gladinet CentreStack and TrioFox on September 27, 2025, and found that three customers had been impacted. The activity involved an unauthenticated local file inclusion flaw that could disclose system files and support a chain to remote code execution through the previously known CVE-2025-30406 path.