CVE-2025-30406
Essential information
- Published
- 03/04/2025 20:15
- Modified
- 03/04/2025 20:15
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, which enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: the CentreStack admin can manually delete the machineKey defined in portal\web.config.
NVD status
- Status
- Received — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| gladinet / centrestack | cpe:2.3:a:gladinet:centrestack:16.1.10296.56315-*:*:*:*:*:*:* |
| gladinet / centrestack | cpe:2.3:a:gladinet:centrestack:<16.4.10315.56368:*:*:*:*:*:*:* |