PT-2025-41413 · Gladinet · Triofox +1

Bryan Masters

+3

·

Published

2025-10-09

·

Updated

2026-01-09

·

CVE-2025-11371

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gladinet CentreStack and Triofox versions prior to and including 16.7.10368.56560
Description Gladinet CentreStack and Triofox are affected by an unauthenticated Local File Inclusion flaw. This allows unintended disclosure of system files and, potentially, remote code execution. Exploitation of this issue has been observed in the wild, with reports of active exploitation by the CL0P ransomware group and other threat actors. At least three customers have been impacted. The vulnerability allows attackers to access system files without authentication, potentially leading to the retrieval of machine keys and subsequent remote code execution. The vulnerability is tracked as CVE-2025-11371.
Recommendations For versions prior to and including 16.7.10368.56560, remove the lines of code that enable the exploitable functionality, as recommended by Huntress, understanding that this may impact some platform features.

Exploit

Fix

RCE

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

BDU:2025-13643
CVE-2025-11371

Affected Products

Gladinet Centrestack
Triofox