logo

No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480

ID: 39777307-8898-5150-a4e4-d0590baaed9e

STIX ID: report--39777307-8898-5150-a4e4-d0590baaed9e

Feed Name: Threat Intelligence

Threat Score
80/100

Date Published: 2025-11-10

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant reports that an unauthenticated access vulnerability (CVE-2025-12480) in Gladinet Triofox (version 16.4.10317.56372) was actively exploited by a GTIG-tracked cluster (UNC6485) to create a native admin account, upload and execute payloads, and tunnel RDP via PLINK; the issue was fixed in a later Triofox release and Mandiant validated the remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.