Active Exploitation of Gladinet CentreStack/Triofox Insecure Cryptography Vulnerability
ID: 38d73485-7b50-5f61-b243-1d74676cfad0
STIX ID: report--38d73485-7b50-5f61-b243-1d74676cfad0
Feed Name: Huntress Blog
Threat Score
**Executive summary:** Huntress discloses a critical weakness in Gladinet CentreStack and Triofox where hardcoded AES-derived keys let attackers decrypt/forge access tickets to access web.config (including machineKey), enabling ViewState deserialization and potential RCE; the issue (CVE-2025-14611) has been observed exploited against at least nine organizations with payload downloads (conqueror.exe), associated IoCs and recommended upgrades/mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
