Executive brief
Gladinet CentreStack and Triofox, platforms used for secure file sharing and remote access, contain a critical security flaw due to the use of hardcoded encryption keys. An attacker can exploit this to access sensitive internal files or potentially take full control of the server without needing a password. This vulnerability is currently being exploited in the wild, posing a significant risk to corporate data and infrastructure.
Technical details
The vulnerability stems from the use of hardcoded values within the AES cryptographic implementation in Gladinet CentreStack and Triofox. By leveraging these static keys, a remote, unauthenticated attacker can craft malicious requests to public-facing endpoints. This can lead to arbitrary Local File Inclusion (LFI), allowing the attacker to read sensitive system files. When combined with other exploitation techniques, this flaw can result in a complete system compromise. The issue is addressed in version 16.12.10420.56791 and later.
Affected products
- Gladinet CentreStack prior to 16.12.10420.56791
- Gladinet Triofox prior to 16.12.10420.56791
Timeline
- 2025-12-12: disclosed: Initial report by Huntress
- 2025-12-15: advisory: NVD and CISA publication
- 2025-12-15: exploited: Added to CISA Known Exploited Vulnerabilities (KEV) catalog