CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild
ID: 382f231a-7509-5220-8758-3190bce8b7f3
STIX ID: report--382f231a-7509-5220-8758-3190bce8b7f3
Feed Name: Huntress Blog
**Huntress observed active exploitation of CVE-2025-30406 in Gladinet CentreStack/Triofox servers (hardcoded machineKey enabling ViewState deserialization and RCE), documented multiple compromises across partner organizations, provided IOCs (malicious DLLs, renamed launcher/Centre.exe, attacker IPs), described post-exploitation activity (Cobalt Strike, MeshCentral, lateral movement), and supplied detection and mitigation guidance including patched versions and PowerShell remediation scripts.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
