CVE-2025-11371

Gladinet CentreStack and Triofox: Files or Directories Accessible to External Parties

As of , CVE-2025-11371 in Gladinet CentreStack and Triofox is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 4 November 2025
US federal deadline
25 November 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.92Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module
Fix
Vendor advice: www.centrestack.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.

CISA's description

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

The CVE record's description, from Huntress

CVE published
9 October 2025
Assigned by
Huntress
CVSS
7.5 High (CVSS 3.1, from CISA-ADP)
CWE-552
Files or Directories Accessible to External Parties
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

CentreStack and Triofox: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-14611Hard Coded CryptographicGladinet CentreStack and TriofoxPatch this weekMetasploit module; EPSS 0.530.53

Read further