No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480
ID: 39777307-8898-5150-a4e4-d0590baaed9e
STIX ID: report--39777307-8898-5150-a4e4-d0590baaed9e
Feed Name: Threat Intelligence
Threat Score
Mandiant reports that an unauthenticated access vulnerability (CVE-2025-12480) in Gladinet Triofox (version 16.4.10317.56372) was actively exploited by a GTIG-tracked cluster (UNC6485) to create a native admin account, upload and execute payloads, and tunnel RDP via PLINK; the issue was fixed in a later Triofox release and Mandiant validated the remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
