peter bassill · operator
$ cve CVE-2025-14611 JSON

CVE-2025-14611 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 53.3% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2026-01-05.

Description

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS53.3% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-798
On CISA KEVyes — remediate by 2026-01-05
Public exploitnone known
Published2025-12-12
Last modified2026-06-17

CISA KEV

NameGladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Added2025-12-15
Due2026-01-05
Vendor / productGladinet / CentreStack and Triofox
Ransomware usenone reported

Affected (2)

VendorProduct
gladinetcentrestack
gladinettriofox

References

→ the Explorer  ·  watch your stack  ·  NVD