logo

Gladinet CentreStack and Gladinet Triofox – Critical RCE

ID: 46d16313-b407-5860-be4c-28d6a900280a

STIX ID: report--46d16313-b407-5860-be4c-28d6a900280a

Feed Name: Kudelski Security

Threat Score
88/100

Date Published: 2025-04-16

Date Updated: 2026-07-22

...
...

A critical vulnerability (CVE-2025-30406, CVSS 9.0) in Gladinet CentreStack and Triofox stems from hard-coded ASP.NET machineKey values that allow crafted ViewState deserialization to achieve remote code execution; observed exploitation since March 2025 includes encoded PowerShell side-loading of DLLs, lateral movement, and installation of MeshCentral/MeshAgent via Impacket commands — mitigation includes patching, rotating machineKey values, and monitoring for PowerShell/IIS anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.