PT-2025-14795 · Gladinet · Gladinet Centrestack
Published
2025-04-03
·
Updated
2025-10-11
·
CVE-2025-30406
CVSS v2.0
10
10
Critical
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Gladinet CentreStack versions through 16.1.10296.56315
Gladinet Triofox versions prior to 16.4.10317.56372
Description
Gladinet CentreStack and Triofox are affected by a deserialization vulnerability due to the use of a hardcoded machineKey in the CentreStack portal. This allows threat actors who know the machineKey to serialize a payload for server-side deserialization, achieving remote code execution. The vulnerability has been actively exploited in the wild since March 2025, with reports of exploitation against seven organizations and 120 endpoints. Exploitation techniques observed include PowerShell commands, DLL sideloading, and enumeration of the targeted host and Active Directory environment.
Recommendations
Gladinet CentreStack versions prior to 16.4.10315.56368: Apply the latest updates to ensure the vulnerability is patched and verify the machineKey was rotated.
Gladinet Triofox versions prior to 16.4.10317.56372: Update to the latest version.
If patching is not immediately available, manually rotate the machineKey defined in
portalweb.config
.
Audit logs for indications of access, including logs for access to /portal/script
endpoints.
Limit external access to CentreStack interfaces wherever possible.
Actively monitor for suspicious deserialization activities.Fix
RCE
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Related Identifiers
BDU:2025-04968
CVE-2025-30406
Affected Products
Gladinet Centrestack
References · 145
- https://bdu.fstec.ru/vul/2025-04968 · Security Note
- https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf · Security Note, Vendor Advisory
- https://centrestack.com/p/gce_latest_release.html · Security Note
- https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2025-triofox.pdf · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-30406 · Security Note
- https://twitter.com/shah_sheikh/status/1912046147427774915 · Twitter Post
- https://twitter.com/AndreGironda/status/1911810934856925297 · Twitter Post
- https://twitter.com/transilienceai/status/1920083558460530731 · Twitter Post
- https://twitter.com/GlobalCyberCom/status/1910461593885769774 · Twitter Post
- https://twitter.com/DeepFlowcc/status/1912194174377685379 · Twitter Post
- https://twitter.com/fletch_ai/status/1912415724683030645 · Twitter Post
- https://twitter.com/marylynnjuszcza/status/1912472744261824776 · Twitter Post
- https://twitter.com/Info_Sec_Buzz/status/1910594852934607334 · Twitter Post
- https://twitter.com/transilienceai/status/1911936849406206035 · Twitter Post
- https://twitter.com/moton/status/1912177214394929530 · Twitter Post