logo

CVE-2025-12480 Detection: Hackers Exploit the Now-Patched Unauthenticated Access Control Vulnerability in Gladinet’s Triofox 

ID: 658c446a-a2af-58e8-80e9-5757258dd366

STIX ID: report--658c446a-a2af-58e8-80e9-5757258dd366

Feed Name: SOC Prime Blog

Threat Score
85/100

Date Published: 2025-11-11

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

Mandiant disclosed CVE-2025-12480, a Triofox zero-day (CVSS 9.1) actively exploited by UNC6485 to bypass authentication, create an admin account, and run arbitrary scripts as SYSTEM via the antivirus path; attackers deployed remote access tools (Zoho Assist, AnyDesk), used SSH tunneling and toolsets like Plink/PuTTY, and leveraged IP 84.200.80.252 for payload delivery — users should upgrade to the patched Triofox version and audit admin accounts and antivirus configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.