Executive brief
Gladinet CentreStack and Triofox, platforms used for secure file sharing and remote access, contain a vulnerability that allows unauthorized individuals to access sensitive system files. This flaw can be exploited remotely without any login credentials, potentially leading to the exposure of configuration data or other private information. This vulnerability has been actively exploited in the wild, making immediate patching critical to prevent data theft or further system compromise.
Technical details
An unauthenticated Local File Inclusion (LFI) vulnerability exists in the default installation and configuration of Gladinet CentreStack and Triofox. The flaw (CWE-552) allows a remote, unauthenticated attacker to access files or directories that should be restricted to the local system. By sending a specially crafted network request, an attacker can read sensitive system files, which may contain credentials or configuration details. This vulnerability has been observed in active exploitation. Patches are available in newer releases, such as CentreStack version 16.10.10408.56683.
Affected products
- Gladinet CentreStack All versions prior to and including 16.7.10368.56560
- Gladinet Triofox All versions prior to and including 16.7.10368.56560
Timeline
- 2025-10-09: disclosed: Initial report by Huntress
- 2025-11-04: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-11-04: advisory: NVD publication date