CVE-2025-11371
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
- Affected products
- Gladinet Centrestack, Triofox
- Gladinet Centrestack
- < 16.10.10408.56683
- Gladinet Triofox
- ≤ 16.7.10368.56560
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 92.1% (100th percentile)
- Weakness
- CWE-552
- NVD status
- Analyzed
- Published
- 2025-10-09
Workaround
If you currently utilize either CentreStack or TrioFox, please check your inbox for communication from Gladinet regarding a temporary mitigation while a patch is being developed.
CVE-2025-11371 at NVD
3 known exploits for CVE-2025-11371
Proof-of-concept code and exploit modules indexed by Sploitus