Executive brief
Gladinet Triofox Server Agent is a software component used to facilitate secure remote file access and synchronization for corporate data. A critical vulnerability in this agent allows an unauthenticated attacker to send a specially crafted network request that can crash the service or potentially execute malicious code. This could lead to a complete takeover of the server hosting the agent, resulting in unauthorized access to sensitive corporate files and data.
Technical details
A stack-based buffer overflow vulnerability exists in the WOSDeviceDropFolder.dll component of Gladinet Triofox Server Agent. The GladServerAgentService.exe process listens on TCP port 7878 and fails to properly validate the length of URL paths starting with the '/resources' prefix. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an excessively long URL, leading to memory corruption. Successful exploitation could allow for arbitrary code execution with the privileges of the service, while unsuccessful attempts will result in a denial-of-service condition. The vulnerability was identified in version 17.1.10488.57063.
Affected products
- Gladinet Triofox Server Agent 17.1.10488.57063
Timeline
- 2026-05-27: disclosed: Vulnerability disclosed by Tenable Research.
- 2026-05-27: advisory: NVD published CVE-2026-8363.