In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
History

Thu, 09 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-220
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Oct 2025 17:00:00 +0000

Type Values Removed Values Added
Description In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
Title Gladinet CentreStack and TrioFox Local File Inclusion Flaw
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Huntress

Published:

Updated: 2025-10-09T19:16:23.772Z

Reserved: 2025-10-06T14:00:55.234Z

Link: CVE-2025-11371

cve-icon Vulnrichment

Updated: 2025-10-09T19:16:17.783Z

cve-icon NVD

Status : Received

Published: 2025-10-09T17:15:58.507

Modified: 2025-10-09T20:15:36.067

Link: CVE-2025-11371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.