CVE-2025-11371
Description
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.
This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
Summary dbcve.org
Unauthenticated Local File Inclusion (LFI) vulnerability in Gladinet CentreStack and TrioFox file sync/share platforms. Attackers can read arbitrary system files on the server without authentication by manipulating file path parameters, potentially exposing sensitive configuration data, credentials, or other system files. Exploitation has been observed in the wild.
Mitigation
Apply vendor-supplied patches/updates to address the LFI vulnerability. If no patch is available, implement network-level restrictions (e.g., WAF rules, IP blocking) to mitigate exploitation while a fix is developed.