Junglewise Threat Intelligence

CVE-2025-11371: Gladinet CentreStack and Triofox unauthenticated local file inclusion

CVE-2025-11371 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2025-11-04

Technologies: Gladinet Triofox, Gladinet CentreStack. Vendors: Gladinet.

Executive brief

Gladinet CentreStack and Triofox, platforms used for secure file sharing and remote access, contain a vulnerability that allows unauthorized individuals to access sensitive system files. This flaw can be exploited remotely without any login credentials, potentially leading to the exposure of configuration data or other private information. This vulnerability has been actively exploited in the wild, making immediate patching critical to prevent data theft or further system compromise.

Technical details

An unauthenticated Local File Inclusion (LFI) vulnerability exists in the default installation and configuration of Gladinet CentreStack and Triofox. The flaw (CWE-552) allows a remote, unauthenticated attacker to access files or directories that should be restricted to the local system. By sending a specially crafted network request, an attacker can read sensitive system files, which may contain credentials or configuration details. This vulnerability has been observed in active exploitation. Patches are available in newer releases, such as CentreStack version 16.10.10408.56683.

Affected products

  • Gladinet CentreStack All versions prior to and including 16.7.10368.56560
  • Gladinet Triofox All versions prior to and including 16.7.10368.56560

Timeline

  • 2025-10-09: disclosed: Initial report by Huntress
  • 2025-11-04: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-11-04: advisory: NVD publication date

Related threats