ZeroHour

CVE-2025-14611

KEV PoC moderate

Hard-Coded AES Keys in Gladinet CentreStack and Triofox Enable Unauthenticated LFI

CISA: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

CVSS 4.0
7.1 high
EPSS
53%p99
Published
()
KEV added
AI analysis

Gladinet CentreStack and Triofox versions prior to 16.12.10420.56791 use hardcoded values for their AES cryptoscheme implementation (CWE-798), meaning affected deployments share fixed encryption keys. Because the keys are static, an unauthenticated attacker who sends a specially crafted request to an affected, publicly exposed endpoint can degrade or bypass the cryptographic protections and achieve arbitrary local file inclusion. An attacker gains unauthorized access to protected data, and the flaw can be leveraged on its own or chained with previously disclosed vulnerabilities to achieve code execution and full system compromise. Any organization running self-hosted or MSP-hosted CentreStack or Triofox gateways exposed to the internet is affected. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-15, Huntress has published public proof-of-concept details with observed attacks, and EPSS estimates a 53.3% probability of exploitation within 30 days.

What to do: Upgrade CentreStack and Triofox to version 16.12.10420.56791 or later per vendor instructions; per CISA KEV/BOD 22-01 guidance, apply vendor mitigations promptly or discontinue use of the product if mitigations are unavailable. Because the hardcoded cryptographic values cannot be rotated by administrators, prioritize patching internet-facing instances and review logs for unauthenticated, specially crafted requests and signs of unauthorized access.

Affected
Gladinet CentreStackAll versions prior to 16.12.10420.56791
Gladinet TriofoxAll versions prior to 16.12.10420.56791
Estimated exposure
moderatelikely thousands to low tens of thousands of internet-exposed CentreStack/Triofox instances (estimate) — CentreStack and Triofox are file-sharing and remote-access gateways commonly deployed by MSPs and self-hosted organizations, and public internet scans have historically shown thousands of exposed instances; no authoritative install count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

CISA Known Exploited Vulnerability
Affected
Gladinet CentreStack and Triofox
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
gladinet
Products
centrestack, triofox
Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news