Vulnerabilities

Gladinet Patches Exploited CentreStack Vulnerability

The unauthenticated local file inclusion bug allows attackers to retrieve the machine key and execute code remotely via a ViewState deserialization issue.

The unauthenticated local file inclusion bug allows attackers to retrieve the machine key and execute code remotely via a ViewState deserialization issue.

Gladinet this week released patches for a CentreStack vulnerability that has been exploited in the wild since at least late September.

Tracked as CVE-2025-11371, the issue is described as an unauthenticated file inclusion bug that allows attackers to retrieve system files.

Impacting the default configurations of Gladinet’s CentreStack and TrioFox products, the security defect was exploited in the wild as a zero-day to retrieve a ‘machineKey’ cryptographic key from a configuration file and execute arbitrary code remotely.

To achieve remote code execution, however, the attackers exploited a ViewState deserialization vulnerability, cybersecurity firm Huntress explains.

The ViewState deserialization issue was previously abused in attacks exploiting CVE-2025-30406, a critical-severity CentreStack and Triofox flaw rooted in the presence of hardcoded keys in the applications’ configuration files.

Armed with a hardcoded machineKey, an attacker could bypass ASPX ViewState protections and execute arbitrary code remotely with the privileges of the IIS application pool user. Successful exploitation of the issue could allow attackers to take full control of a vulnerable system.

Advertisement. Scroll to continue reading.

Gladinet patched CVE-2025-30406 in April by updating one of the configuration files containing the machineKey and removing the key from another.

As part of the fresh attacks flagged by Huntress, threat actors are exploiting CVE-2025-11371 to retrieve the configuration file containing the machineKey, which allows them to perform a deserialization attack to execute commands on the vulnerable system.

Gladinet resolved the newly discovered vulnerability in CentreStack version 16.10.10408.56683. Given the flaw’s in-the-wild exploitation, organizations and end users are advised to apply the patches as soon as possible.

CentreStack is a self-hosted, on-premise cloud file server that provides organizations with secure file sharing capabilities. It can be deployed by MSPs for their clients and integrated with existing infrastructure.

Related: In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware

Related: Organizations Warned of Exploited Adobe AEM Forms Vulnerability

Related: Cisco Routers Hacked for Rootkit Deployment

Related: SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM

Related Content

Vulnerabilities

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Endpoint Security

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Vulnerabilities

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

Vulnerabilities

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version