DEV Community

Cover image for CVE-2025-14611: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Freedom Coder
Freedom Coder

Posted on • Originally published at scyscan.com

CVE-2025-14611: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

CVE ID

CVE-2025-14611

Vulnerability Name

Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

  • Project: Gladinet
  • Product: CentreStack and Triofox

Date

  • Date Added: 2025-12-15
  • Due Date: 2026-01-05

Description

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://www.centrestack.com/p/gce_latest_release.html ; https://access.triofox.com/releases_history/; https://support.centrestack.com/hc/en-us/articles/360007159054-Hardening-the-CentreStack-Cluster#h_01JQRV57T37HJFQZKBZH9NBXQP ; https://nvd.nist.gov/vuln/detail/CVE-2025-14611

More CVEs Info

Common Vulnerabilities & Exposures (CVE) List

Top comments (0)