Executive brief
Gladinet Triofox, a platform used for secure remote file access and collaboration, contains a security flaw that allows unauthorized users to access initial configuration pages. This could allow an attacker to reconfigure the system, potentially leading to a full takeover of the environment or theft of sensitive corporate data. This vulnerability is known to be actively exploited in the wild.
Technical details
An improper access control vulnerability (CWE-284) exists in Gladinet Triofox versions prior to 16.7.10368.56560. The flaw allows unauthenticated remote attackers to access administrative setup and configuration pages that should be restricted once the initial installation is complete. By accessing these pages, an attacker can modify system settings or gain administrative control over the platform. This vulnerability has been observed being exploited in the wild. Users should update to version 16.7.10368.56560 or later to remediate the issue.
Affected products
- Gladinet Triofox Prior to 16.7.10368.56560
Timeline
- 2025-11-10: advisory: Initial advisory published by Mandiant
- 2025-11-12: kev added: CISA added to Known Exploited Vulnerabilities catalog
- 2025-11-12: exploited: Confirmed active exploitation in the wild