logo

Active Exploitation of Gladinet CentreStack/Triofox Insecure Cryptography Vulnerability

ID: 38d73485-7b50-5f61-b243-1d74676cfad0

STIX ID: report--38d73485-7b50-5f61-b243-1d74676cfad0

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-12-18

Date Updated: 2026-04-28

...
...

**Executive summary:** Huntress discloses a critical weakness in Gladinet CentreStack and Triofox where hardcoded AES-derived keys let attackers decrypt/forge access tickets to access web.config (including machineKey), enabling ViewState deserialization and potential RCE; the issue (CVE-2025-14611) has been observed exploited against at least nine organizations with payload downloads (conqueror.exe), associated IoCs and recommended upgrades/mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.