CVE-2025-11371
⚡ CISA KEVPublished: —Modified: —Vendor: GladinetProduct: CentreStack and Triofox
—
CVSS v3
92.1%
EPSS
⚡ Added to KEV on 2025-11-04 · Federal agencies must remediate by 2025-11-25
Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules0
Rules tagged with this CVE
No Sigma rules tagged with this CVE.
🛠️ Patch Details5
Affected/fixed versions from threat intel reports
📰 Threat Intel Coverage9
Digest reports mentioning this CVE
| Gladinet CentreStack/Triofox: Cryptography Vulnerability | Huntress | huntress | 2025-12-18 |
| Exploitation of Windows Server Update Services Remote Code | Huntress | huntress | 2025-10-24 |
| Active Exploitation of Gladinet CentreStack and Triofox | Huntress | huntress | 2025-10-15 |
| Post-Exploitation Activities Observed from the Samsung | Huntress | huntress | 2025-05-09 |
| Do Tigers Really Change Their Stripes? | Huntress | huntress | 2025-05-06 |
| CVE-2025-30406: Gladinet CentreStack & Triofox Exploited | Huntress | huntress | 2025-04-14 |
| CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation | Huntress | huntress | 2025-04-04 |
| Critical Vulnerabilities: WS_FTP Exploitation | Huntress | huntress | 2023-10-02 |
| CVE-2017-18362: SQL Injection in ManagedITSync Integration | Huntress | huntress | 2019-02-08 |
📎 References0
No reference URLs.