CVE-2025-14611
Gladinet CentreStack and Triofox: Hard Coded Cryptographic
As of , CVE-2025-14611 in Gladinet CentreStack and Triofox is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 15 December 2025
- US federal deadline
- 5 January 202621 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.53Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: access.triofox.com, support.centrestack.com and www.centrestack.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.
CISA's description
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
The CVE record's description, from Huntress
- CVE published
- 12 December 2025
- Assigned by
- Huntress
- CVSS
- 7.1 High (CVSS 4.0, from the CNA)
- CWE-798
- Use of Hard-coded Credentials
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Gladinet CentreStack/Triofox Access Ticket Forgeauxiliary module, rank normal
CentreStack and Triofox: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-11371Files or Directories Accessible to External Parties | Gladinet CentreStack and Triofox | Patch this weekMetasploit module; EPSS 0.92 | 0.92 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org