CVE-2025-14611
KEV PoC moderateHard-Coded AES Keys in Gladinet CentreStack and Triofox Enable Unauthenticated LFI
CISA: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Gladinet CentreStack and Triofox versions prior to 16.12.10420.56791 use hardcoded values for their AES cryptoscheme implementation (CWE-798), meaning affected deployments share fixed encryption keys. Because the keys are static, an unauthenticated attacker who sends a specially crafted request to an affected, publicly exposed endpoint can degrade or bypass the cryptographic protections and achieve arbitrary local file inclusion. An attacker gains unauthorized access to protected data, and the flaw can be leveraged on its own or chained with previously disclosed vulnerabilities to achieve code execution and full system compromise. Any organization running self-hosted or MSP-hosted CentreStack or Triofox gateways exposed to the internet is affected. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-15, Huntress has published public proof-of-concept details with observed attacks, and EPSS estimates a 53.3% probability of exploitation within 30 days.
What to do: Upgrade CentreStack and Triofox to version 16.12.10420.56791 or later per vendor instructions; per CISA KEV/BOD 22-01 guidance, apply vendor mitigations promptly or discontinue use of the product if mitigations are unavailable. Because the hardcoded cryptographic values cannot be rotated by administrators, prioritize patching internet-facing instances and review logs for unauthenticated, specially crafted requests and signs of unauthorized access.
| Gladinet CentreStack | All versions prior to 16.12.10420.56791 |
| Gladinet Triofox | All versions prior to 16.12.10420.56791 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
- Affected
- Gladinet CentreStack and Triofox
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- gladinet
- Products
- centrestack, triofox
- Weakness
- CWE-798
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X