CVE-2025-14611

Gladinet CentreStack and Triofox: Hard Coded Cryptographic

As of , CVE-2025-14611 in Gladinet CentreStack and Triofox is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 15 December 2025
US federal deadline
5 January 202621 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.53Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module
Fix
Vendor advice: access.triofox.com, support.centrestack.com and www.centrestack.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

CISA's description

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

The CVE record's description, from Huntress

CVE published
12 December 2025
Assigned by
Huntress
CVSS
7.1 High (CVSS 4.0, from the CNA)
CWE-798
Use of Hard-coded Credentials
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

CentreStack and Triofox: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-11371Files or Directories Accessible to External PartiesGladinet CentreStack and TriofoxPatch this weekMetasploit module; EPSS 0.920.92

Read further