peter bassill · operator
$ cve CVE-2025-12480 JSON

CVE-2025-12480 KEV

9.1
CRITICAL · CVSS 3.1 · EPSS 95.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-12-03.

Description

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS95.43% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-284
On CISA KEVyes — remediate by 2025-12-03
Public exploitnone known
Published2025-11-10
Last modified2026-06-17

CISA KEV

NameGladinet Triofox Improper Access Control Vulnerability
Added2025-11-12
Due2025-12-03
Vendor / productGladinet / Triofox
Ransomware usenone reported

Affected (1)

VendorProduct
gladinettriofox

References

→ the Explorer  ·  watch your stack  ·  NVD