Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave Security Patch Release

Gladinet machine-key exploitation chain

Updated 11.12.2025 23:49
Case score 69
Case score 69 Members 5 Latest activity 11.12.2025 23:49
Active exploitation KEV: CISA KEV Patch status varies by member CVSS: 9.8 Critical
Members 5 First seen 10.10.2025 12:34 Last seen 11.12.2025 23:49 Updated 11.12.2025 23:49

Overview

Attackers are exploiting **Gladinet CentreStack** and **Triofox** by abusing hardcoded AES keys and access-ticket handling to recover `Web.config`, steal the ASP.NET machine key, and reach **remote code execution**. Huntress said the activity had already targeted **at least nine organizations**, used crafted requests from `147.124.216[.]205`, and relied on `/storage/filesvr.dn` traffic to forge or decrypt tickets. Gladinet released **CentreStack 16.10.10408.56683** for **CVE-2025-11371** and told administrators to install it. If upgrading is not possible, the temporary mitigation is to disable the temp handler in `UploadDownloadProxy/Web.config`, which can affect some platform functionality.

Signals

10 derived
Exploitation
Exploitation Active exploitation CVSS 9.8 Critical
Affected impact
Affected service
CVEs/products
CVE CVE
Victims/regions
Sector healthcare
Remediation
Remediation Urgency High KEV CISA KEV
Data exposure
Leak status Exposed/Unsecured

Malware context

0 families · 1 tools
Tools
PowerShell Invoke-WebRequest

Member happenings

5 related
Vulnerability Gladinet CentreStack and Triofox hardcoded AES keys RCE flaw
Updated 11.12.2025 23:49 Lead Contribution 64
Exploitation Active Exploitation Data Type Passwords Data Type Usernames Patch Patch Available

A new **Gladinet CentreStack** and **Triofox** vulnerability in the products' custom AES implementation is being **actively exploited** to recover **hardcoded cryptographic keys** and enable **remote code execution**. **Gladinet** told customers to upgrade and rotate machine keys, while researchers said the abuse had already targeted **at least nine organizations**. The flaw affects secure remote file access and sharing systems, making exposed deployments a direct takeover risk.

Exploitation Wave Gladinet CentreStack and Triofox active exploitation wave
Updated 11.12.2025 07:56 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

Active exploitation of **Gladinet CentreStack** and **Triofox** has affected **at least nine organizations**, creating risk of unauthorized access and follow-on **remote code execution**. Attack traffic has been observed from **147.124.216[.]205** using crafted requests to **/storage/filesvr.dn** and forged access tickets. The activity also appears to chain the new abuse with **CVE-2025-11371** to reach **web.config** and obtain the machine key.

Vulnerability Gladinet CentreStack and TrioFox actively exploited unauthenticated LFI remote code execution flaw (multiple vulnerabilities)
Updated 10.10.2025 12:34 Scoring Support Contribution 2
Exploitation Active Exploitation Data Type Source Code CVSS 9.8 Critical Data Status Exposed/Unsecured

**Gladinet CentreStack** is now patched for **CVE-2025-11371**, an **unauthenticated local file inclusion** flaw that threat actors have used as a **zero-day** since **late September**. The bug let attackers read `Web.config`, extract the ASP.NET machine key, and chain into **CVE-2025-30406** for **remote code execution** on affected deployments. Gladinet says the fix is available in **CentreStack version 16.10.10408.56683**, and administrators are strongly recommended to install it. If upgrading is not possible, the interim mitigation is to disable the **temp handler** in `UploadDownloadProxy/Web.config`.

Security Patch Release CentreStack security update for CVE-2025-11371
Updated 16.10.2025 18:11 Context
Exploitation Active Exploitation Urgency High Patch Patch Available

**Gladinet** released a **security update** for **CentreStack** to fix **CVE-2025-11371**, a **zero-day** local file inclusion flaw affecting business file-sharing deployments. The issue had been abused since **late September** and could expose **Web.config** on fully patched systems, letting attackers extract the **ASP.NET machine key**. The new build, **version 16.10.10408.56683**, is available now, and administrators are **strongly recommended** to install it. If upgrading is not possible, a temporary mitigation is to disable the **temp handler** in **Web.config** for the **UploadDownloadProxy** component.

Advisory/Mitigation Gladinet CentreStack and Triofox workaround for CVE-2025-11371
Updated 10.10.2025 22:08 Context
Exploitation Active Exploitation Urgency High

**CentreStack** and **Triofox** are affected by **CVE-2025-11371**, a **local file inclusion zero-day** that threat actors have **abused since late September** to read **Web.config**, extract the ASP.NET machine key, and chain into **CVE-2025-30406** for **remote code execution**. **Gladinet** has released **version 16.10.10408.56683** to fix the issue and previously advised a **temporary workaround** for customers who cannot upgrade. The workaround disables the **temp handler** in **Web.config** for the **UploadDownloadProxy** component, but it can **impact some functionality**.