Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Gladinet Patches Exploited CentreStack Vulnerability

The unauthenticated local file inclusion bug allows attackers to retrieve the machine key and execute code remotely via a ViewState deserialization issue.

Gladinet this week released patches for a CentreStack vulnerability that has been exploited in the wild since at least late September.

Tracked as CVE-2025-11371, the issue is described as an unauthenticated file inclusion bug that allows attackers to retrieve system files.

Impacting the default configurations of Gladinet’s CentreStack and TrioFox products, the security defect was exploited in the wild as a zero-day to retrieve a ‘machineKey’ cryptographic key from a configuration file and execute arbitrary code remotely.

To achieve remote code execution, however, the attackers exploited a ViewState deserialization vulnerability, cybersecurity firm Huntress explains.

The ViewState deserialization issue was previously abused in attacks exploiting CVE-2025-30406, a critical-severity CentreStack and Triofox flaw rooted in the presence of hardcoded keys in the applications’ configuration files.

Armed with a hardcoded machineKey, an attacker could bypass ASPX ViewState protections and execute arbitrary code remotely with the privileges of the IIS application pool user. Successful exploitation of the issue could allow attackers to take full control of a vulnerable system.

Advertisement. Scroll to continue reading.

Gladinet patched CVE-2025-30406 in April by updating one of the configuration files containing the machineKey and removing the key from another.

As part of the fresh attacks flagged by Huntress, threat actors are exploiting CVE-2025-11371 to retrieve the configuration file containing the machineKey, which allows them to perform a deserialization attack to execute commands on the vulnerable system.

Gladinet resolved the newly discovered vulnerability in CentreStack version 16.10.10408.56683. Given the flaw’s in-the-wild exploitation, organizations and end users are advised to apply the patches as soon as possible.

CentreStack is a self-hosted, on-premise cloud file server that provides organizations with secure file sharing capabilities. It can be deployed by MSPs for their clients and integrated with existing infrastructure.

Related: In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware

Related: Organizations Warned of Exploited Adobe AEM Forms Vulnerability

Related: Cisco Routers Hacked for Rootkit Deployment

Related: SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.