logo

CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild

ID: 382f231a-7509-5220-8758-3190bce8b7f3

STIX ID: report--382f231a-7509-5220-8758-3190bce8b7f3

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2025-04-14

Date Updated: 2026-04-28

...
...

**Huntress observed active exploitation of CVE-2025-30406 in Gladinet CentreStack/Triofox servers (hardcoded machineKey enabling ViewState deserialization and RCE), documented multiple compromises across partner organizations, provided IOCs (malicious DLLs, renamed launcher/Centre.exe, attacker IPs), described post-exploitation activity (Cobalt Strike, MeshCentral, lateral movement), and supplied detection and mitigation guidance including patched versions and PowerShell remediation scripts.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.