Gladinet CentreStack and Gladinet Triofox – Critical RCE
ID: 46d16313-b407-5860-be4c-28d6a900280a
STIX ID: report--46d16313-b407-5860-be4c-28d6a900280a
Feed Name: Kudelski Security
A critical vulnerability (CVE-2025-30406, CVSS 9.0) in Gladinet CentreStack and Triofox stems from hard-coded ASP.NET machineKey values that allow crafted ViewState deserialization to achieve remote code execution; observed exploitation since March 2025 includes encoded PowerShell side-loading of DLLs, lateral movement, and installation of MeshCentral/MeshAgent via Impacket commands — mitigation includes patching, rotating machineKey values, and monitoring for PowerShell/IIS anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
