{"id":7565,"date":"2025-10-10T10:03:04","date_gmt":"2025-10-10T10:03:04","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/10\/gladinet-centrestack-and-triofox-0-day-rce-vulnerability-actively-exploited-in-attacks\/"},"modified":"2025-10-10T10:03:04","modified_gmt":"2025-10-10T10:03:04","slug":"gladinet-centrestack-and-triofox-0-day-rce-vulnerability-actively-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/10\/gladinet-centrestack-and-triofox-0-day-rce-vulnerability-actively-exploited-in-attacks\/","title":{"rendered":"Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks"},"content":{"rendered":"<p>    Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An active in-the-wild exploitation of a <a href=\"https:\/\/cybersecuritynews.com\/tag\/zero-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerability<\/a> in Gladinet CentreStack and Triofox products. Tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-11371\">CVE-2025-11371<\/a>, the unauthenticated Local File Inclusion (LFI) flaw allows attackers to achieve remote code execution (RCE) on affected systems.<\/p>\n<p>The vulnerability is currently unpatched, but a mitigation has been provided. Organizations using the affected software are strongly urged to apply the workaround immediately to prevent compromise, as Huntress has confirmed attacks against multiple customers.<\/p>\n<p>The flaw represents a significant threat, enabling attackers to bypass a previous security fix and take control of vulnerable servers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-new-attack-bypasses-previous-security-patch\"><strong>New Attack Bypasses Previous Security Patch<\/strong><\/h2>\n<p>The discovery of this zero-day exploitation followed Huntress analysts\u2019 investigation of an alert on September 27, 2025.<\/p>\n<p>The alert, which flagged suspicious activity on a server running Gladinet CentreStack, was initially believed to be related to a previously disclosed vulnerability, CVE-2025-30406. <\/p>\n<p>That flaw, reported by Huntress in April 2025, involved a hardcoded machine key that could be abused for RCE through a ViewState deserialization attack. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_dgcvxPMyPrWIomVOXtb1UfX7xhqZuGhBbCEgCcC8FrguuGKdZ7vPh2-g0GMvBp3iEMiB0KF9iKvoL7WCHfaCC-4BoINMnTm0V_HcAiIVJCxzDujLfNcOzTQ0pS6ici5cp5B6oBykUYOC0xf5n2Hm-ZIrmyad3oNIz2mhnDIQRa7fWrXqMmlZZb8g8Iyc\/s1480\/assets_3eb6f92aedf74..._imresizer.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>However, the targeted system was running a version that had been patched against CVE-2025-30406. Further analysis revealed a new, sophisticated attack chain. <\/p>\n<p>Threat actors were exploiting the <a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-pdf-export-lfi-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">LFI vulnerability<\/a>, CVE-2025-11371, to read the file and extract the machine key. With this key, they could then leverage the same ViewState deserialization method from the earlier vulnerability to execute arbitrary code.<\/p>\n<p>This technique effectively renders the patch for CVE-2025-30406 insufficient on its own, creating a new path for attackers to achieve the same devastating impact.<\/p>\n<p>Huntress confirmed that this is not a theoretical threat, having observed the exploit used against three of its customers. <\/p>\n<p>The first signs of an attack were detected on September 26, 2025, when an internal monitor alerted the Huntress <a href=\"https:\/\/cybersecuritynews.com\/what-is-a-security-operations-center\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security Operations Center (SOC)<\/a> to an anomalous base64 payload being executed as a child process of a web server.<\/p>\n<p>Upon confirming the threat, the analyst immediately contained the compromised host to prevent further malicious activity. <\/p>\n<p>During its investigation, Huntress <a href=\"https:\/\/www.huntress.com\/blog\/gladinet-centrestack-triofox-local-file-inclusion-flaw\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovered that<\/a> Gladinet had already engaged with a mutual customer to implement a workaround, indicating the vendor was aware of the issue.<\/p>\n<p>Following its standard disclosure policy, Huntress contacted Gladinet, which confirmed its awareness and stated it was in the process of notifying customers about the necessary mitigation. Huntress has also directly informed its own impacted partners of the workaround.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations\"><strong>Mitigations<\/strong><\/h2>\n<p>With no official patch yet available and active exploitation confirmed, applying the recommended mitigation is critical for all organizations using CentreStack and Triofox. <\/p>\n<p>According to the guidance, administrators must disable the <code>temp<\/code> handler within the file for the <code>UploadDownloadProxy<\/code>. The configuration file is typically located at. <\/p>\n<p>Removing the specified handler line will disrupt some platform functionality, but it effectively closes the attack vector until Gladinet releases a permanent patch.<\/p>\n<p>Given the severity of the RCE vulnerability and the proven ability of threat actors to exploit it, system administrators should treat this mitigation as an urgent priority to protect their environments from takeover. <\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gladinet-centrestack-and-triofox-0-day-rce\/\">Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gladinet-centrestack-and-triofox-0-day-rce\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks An active in-the-wild exploitation of a zero-day vulnerability in Gladinet CentreStack and Triofox products. Tracked as CVE-2025-11371, the unauthenticated Local File Inclusion (LFI) flaw allows attackers to achieve remote code execution (RCE) on affected systems. The vulnerability is currently unpatched, but a mitigation has [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7565","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7565"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7565"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7565\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}