216.73.217.22

CVE-2025-11371

· Published 09/10/2025 17:15 · Modified 10/10/2025 14:15

Labels: CVE-2025-11371 2025-10-095dacb0b8-2277-4717-899c-254586fe4912CVE-2025-11371CWE-220CWE-552

Essential information

Published
09/10/2025 17:15
Modified
10/10/2025 14:15
Author
Creator
CVSS
6.2 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5dacb0b8-2277-4717-899c-254586fe4912
NVD
View on NVD

Affected products (CPE)

ProductCPE
gladinet / centrestack cpe:2.3:a:gladinet:centrestack:<16.7.10368.56560:*:*:*:*:*:*:*
gladinet / triofox cpe:2.3:a:gladinet:triofox:<16.7.10368.56560:*:*:*:*:*:*:*

References