Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Google rolls out AI ‘flight ticket’ tool globally, adds new travel features to search

New Assessment ClickFix Campaign Offers Amatera Stealer and NetSupport RAT

PowerLattice attracts investment from former Intel CEO Pat Gelsinger for power-saving chiplets

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Active exploit detected for Gladinet and TrioFox vulnerabilities
Identity

Active exploit detected for Gladinet and TrioFox vulnerabilities

userBy userOctober 10, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 10, 2025Ravi LakshmananVulnerability/Zero-day

Gladinet and TrioFox vulnerabilities

Cybersecurity firm Huntress said it has seen active exploitation of an unpatched security flaw affecting its Gladinet CentreStack and TrioFox products in the wild.

The zero-day vulnerability, tracked as CVE-2025-11371 (CVSS score: 6.1), is an unauthenticated local file inclusion bug that allows unintentional disclosure of system files. This affects all versions of the software prior to 16.7.10368.56560.

Huntress said it first detected this activity on September 27, 2025, and so far three of its customers have been found to be affected.

It is worth noting that both applications were previously affected by CVE-2025-30406 (CVSS score: 9.0). This is a case of a hard-coded machine key, which could allow a threat actor to perform remote code execution via a ViewState deserialization vulnerability. This vulnerability has since been exploited.

CIS build kit

According to Huntress, CVE-2025-11371 “allowed a threat actor to obtain a machine key from an application’s Web.config file and execute remote code via the ViewState deserialization vulnerability described above. Additional details of this flaw are pending in light of active investigation and absence of a patch.”

In one case the company investigated, the affected version was newer than 16.4.10315.56368 and was not vulnerable to CVE-2025-30406. This suggests that an attacker could exploit an earlier version and use a hardcoded machine key to remotely execute code via a flaw in ViewState deserialization.

In the meantime, we recommend disabling the “temp” handler in the Web.config file for UploadDownloadProxy located at “C:\Program Files (x86)\Gladinet Cloud Enterprise\UploadDownloadProxy\Web.config”.

“While this impacts some functionality on the platform, it ensures that this vulnerability cannot be exploited until it is patched,” said Huntress researchers Brian Masters, James McLachlan, Jay Minton and John Hammond.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDelivering immersive technology while saving energy
Next Article Too good to be true? How Q-Field protects your room from germs
user
  • Website

Related Posts

New Assessment ClickFix Campaign Offers Amatera Stealer and NetSupport RAT

November 17, 2025

Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More

November 17, 2025

5 reasons why attackers phish through LinkedIn

November 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Google rolls out AI ‘flight ticket’ tool globally, adds new travel features to search

New Assessment ClickFix Campaign Offers Amatera Stealer and NetSupport RAT

PowerLattice attracts investment from former Intel CEO Pat Gelsinger for power-saving chiplets

Luminal raises $5.3 million to build a better GPU code framework

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.