Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw
ID: 34cc25de-653f-53fe-9c12-a3636d1f7bd7
STIX ID: report--34cc25de-653f-53fe-9c12-a3636d1f7bd7
Feed Name: Huntress Blog
**Huntress discovered active exploitation of an unauthenticated Local File Inclusion (CVE-2025-11371) in Gladinet CentreStack and Triofox that allowed attackers to retrieve Web.config (and the machine key) and chain this to a ViewState deserialization remote code execution (CVE-2025-30406).** The report documents observed GET/POST requests, base64 payloads, captured logs showing command execution, a PowerShell one-liner PoC for the LFI, mitigation (disable the temp handler) and notes that Gladinet released a patch (version 16.10.10408.56683) — impacted organizations should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
