CVE-2025-30406
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.
- Affected products
- Gladinet Centrestack
- Gladinet Centrestack
- < 16.4.10315.56368
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 93.8% (100th percentile)
- Weakness
- CWE-798, CWE-321
- NVD status
- Analyzed
- Published
- 2025-04-03
CVE-2025-30406 at NVD
6 known exploits for CVE-2025-30406
Proof-of-concept code and exploit modules indexed by Sploitus
Gladinet CentreStack/Triofox Path Traversal
Exploit for Use of Hard-coded Credentials in Gladinet Centrestack
Exploit for CVE-2025-11371
Exploit for Use of Hard-coded Cryptographic Key in Gladinet Centrestack
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
π Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization