By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability
Computing

From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability

News Room
Last updated: 2025/10/10 at 5:55 AM
News Room Published 10 October 2025
Share
From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability
SHARE

Oct 10, 2025Ravie LakshmananVulnerability / Zero-Day

Cybersecurity company Huntress said it has observed active in-the-wild exploitation of an unpatched security flaw impacting Gladinet CentreStack and TrioFox products.

The zero-day vulnerability, tracked as CVE-2025-11371 (CVSS score: 6.1), is an unauthenticated local file inclusion bug that allows unintended disclosure of system files. It impacts all versions of the software prior to and including 16.7.10368.56560.

Huntress said it first detected the activity on September 27, 2025, uncovering that three of its customers have been impacted so far.

It’s worth noting that both applications were previously affected by CVE-2025-30406 (CVSS score: 9.0), a case of hard-coded machine key that could allow a threat actor to perform remote code execution via a ViewState deserialization vulnerability. The vulnerability has since come under active exploitation.

CIS Build Kits

CVE-2025-11371, per Huntress, “allowed a threat actor to retrieve the machine key from the application Web.config file to perform remote code execution via the aforementioned ViewState deserialization vulnerability. Additional details of the flaw are being withheld in light of active exploration and in the absence of a patch.

In one instance investigated by the company, the affected version was newer than 16.4.10315.56368 and not vulnerable to CVE-2025-30406, suggesting that attackers could exploit earlier versions and use the hard-coded machine key to execute code remotely via the ViewState deserialization flaw.

In the interim, users are recommended to disable the “temp” handler within the Web.config file for UploadDownloadProxy located at “C:Program Files (x86)Gladinet Cloud EnterpriseUploadDownloadProxyWeb.config.”

“This will impact some functionality of the platform; however, it will ensure that this vulnerability cannot be exploited until it is patched,” Huntress researchers Bryan Masters, James Maclachlan, Jai Minton, and John Hammond said.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Belkin Launches Hybrid Camera Grip and Power Bank Belkin Launches Hybrid Camera Grip and Power Bank
Next Article Discord Security Breach Exposed Government ID Photos of 70,000 Users Discord Security Breach Exposed Government ID Photos of 70,000 Users
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Ditch the Subscription: Get Microsoft Office 2019 for Mac Under
Ditch the Subscription: Get Microsoft Office 2019 for Mac Under $40
News
TikTok signs Trump-backed deal to avoid US ban
TikTok signs Trump-backed deal to avoid US ban
News
Best streaming deal: Save  on Roku Streaming Stick 4K
Best streaming deal: Save $20 on Roku Streaming Stick 4K
News
Why ABA Assessments Matter: A Maryland Parent’s Guide to Personalized Behavior Support
Why ABA Assessments Matter: A Maryland Parent’s Guide to Personalized Behavior Support
Gadget

You Might also Like

BYD to roll out new-gen blade batteries in 2025: report · TechNode
Computing

BYD to roll out new-gen blade batteries in 2025: report · TechNode

1 Min Read
Tencent to cease online services for Chinese version of Nintendo Switch by March 2026 · TechNode
Computing

Tencent to cease online services for Chinese version of Nintendo Switch by March 2026 · TechNode

1 Min Read
Shanghai Consumer Council criticizes auto-renewal practices on major apps · TechNode
Computing

Shanghai Consumer Council criticizes auto-renewal practices on major apps · TechNode

1 Min Read
CATL partners with China’s Changan to boost battery swap business · TechNode
Computing

CATL partners with China’s Changan to boost battery swap business · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?