HIGH

CVE-2025-11371

Gladinet Centrestack 2025-10-09 CVSS v3.1
CVSS
7.5
KEV

Description

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. 

This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

Summary dbcve.org

Unauthenticated Local File Inclusion (LFI) vulnerability in Gladinet CentreStack and TrioFox file sync/share platforms. Attackers can read arbitrary system files on the server without authentication by manipulating file path parameters, potentially exposing sensitive configuration data, credentials, or other system files. Exploitation has been observed in the wild.

Mitigation

Apply vendor-supplied patches/updates to address the LFI vulnerability. If no patch is available, implement network-level restrictions (e.g., WAF rules, IP blocking) to mitigate exploitation while a fix is developed.

Proof of Concept

Weakness (CWE)

CWE-552

EPSS Score

92.14%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE