Executive brief
Gladinet CentreStack and Triofox contain a hard-coded cryptographic machineKey used for ViewState integrity verification. An attacker can use this key to forge serialized payloads, leading to server-side deserialization and remote code execution.
Affected products
- Gladinet CentreStack through 16.1.10296.56315
- Gladinet Triofox
Timeline
- 2025-03: exploited: Exploited in the wild.
- 2025-04-03: disclosed: NVD Published Date.
- 2025-04-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2025-04-08: advisory: Published date.
- patched: Fixed in version 16.4.10315.56368.