CVE-2025-14611

Gladinet CentreStack and TrioFox Hard Coded AES Keys

Basic Information

CVE State
PUBLISHED
Reserved Date
December 12, 2025
Published Date
December 12, 2025
Last Updated
February 26, 2026
Vendor
Gladinet
Product
CentreStack and TrioFox
Description
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
Tags
cisa nuclei_scanner

CVSS Scores

CVSS v4.0

7.1 - HIGH

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:46:18 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:46:18 UTC

Scanner Integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei