216.73.217.22

Active Exploitation of Gladinet CentreStack/Triofox Insecure Cryptography Vulnerability

· Published 11/12/2025 18:25 · Modified 21/12/2025 19:01

Export JSON

Essential information

Published
11/12/2025 18:25
Modified
21/12/2025 19:01
Tags
2025-12-11 CVE-2025-11371 access ticket aes centrestack cryptography deserialization remote code execution triofox vulnerability
Related entities
1 vulnerabilities (cve), 1 observables, 7 techniques (mitre), 2 others

Description

A critical in Gladinet's and products has been discovered, involving hardcoded cryptographic keys in their implementation. This flaw allows potential access to the web.config file, enabling and . Attackers are actively targeting this across various organizations. The issue stems from static encryption keys derived from unchanging Chinese and Japanese text strings, allowing for decryption and creation of access tickets. Exploitation attempts have been observed across multiple sectors, with attackers using the to obtain machine keys and perform viewstate attacks. Immediate updates to the latest version and machine key rotation are recommended for mitigation.

External references