Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

EU invests €358 million in new LIFE program projects

Blue Origin cancels second New Glenn launch, will try again on November 12th

Slow Ventures hosts a ‘finishing school’ to help founders learn to be fancy

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds Gladinet and CWP flaws to KEV catalog amid evidence of active exploitation
Identity

CISA adds Gladinet and CWP flaws to KEV catalog amid evidence of active exploitation

userBy userNovember 5, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 5, 2025Ravi LakshmananVulnerability/Network Security

CISA adds Gladinet and CWP flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws affecting Gladinet and Control WebPanel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of real-world exploitation.

The vulnerabilities in question are as follows.

CVE-2025-11371 (CVSS Score: 7.5) – A vulnerability exists in an externally accessible file or directory in Gladinet CentreStack and Triofox that could lead to the unintentional disclosure of system files. CVE-2025-48703 (CVSS Score: 9.0) – Operating system command injection vulnerability in the Control Web Panel (formerly CentOS Web Panel) allows unauthenticated remote code execution via a shell metacharacter in the t_total parameter of a file manager changePerm request.

This development comes weeks after cybersecurity firm Huntress announced it had detected an active exploitation attempt targeting CVE-2025-11371, in which an unknown attacker is leveraging the flaw to execute reconnaissance commands (e.g. ipconfig /all) passed in the form of a Base64-encoded payload.

DFIR retainer service

However, there are currently no published reports on how CVE-2025-48703 is being weaponized in real-world attacks. However, the technical details of this flaw were shared by security researcher Maxime Rinaudo in June 2025, shortly after it was patched with version 0.9.8.1205 following a responsible disclosure on May 13th.

“This allows a remote attacker who knows a valid username on a CWP instance to execute arbitrary pre-authenticated commands on the server,” Rinaudo said.

In view of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have until November 25, 2025 to apply the necessary fixes to secure their networks.

The addition of the two flaws to the KEV catalog follows a report by Wordfence about the exploitation of a critical security vulnerability affecting three WordPress plugins and themes.

CVE-2025-11533 (CVSS Score: 9.8) – Privilege escalation vulnerability in WP Freeio allows an unauthenticated attacker to grant themselves administrative privileges by specifying a user role during registration. CVE-2025-5397 (CVSS Score: 9.8) – Authentication bypass vulnerability in Noo JobMonster allows unauthenticated attackers to bypass standard authentication and gain access to administrative user accounts, assuming social login is enabled on a site. CVE-2025-11833 (CVSS score: 9.8) – Missing authentication check in Post SMTP allows unauthenticated attackers to view email logs, including password reset emails, and change the passwords of arbitrary users, including administrators, and take over the site.

WordPress site users who rely on the aforementioned plugins and themes are encouraged to update to the latest versions as soon as possible, use strong passwords, and audit their sites for signs of malware or the presence of unexpected accounts.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAmazon sends legal threat to Perplexity over agent browsing
Next Article Millions of people in the UK are at risk of PFAS in tap water
user
  • Website

Related Posts

Microsoft discovers ‘whisper leak’ attack that identifies AI chat topics in encrypted traffic

November 8, 2025

Samsung’s zero-click flaw is exploited to deploy LANDFALL Android spyware via WhatsApp

November 7, 2025

From Log4j to IIS, Chinese hackers turn legacy bugs into global spying tools

November 7, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

EU invests €358 million in new LIFE program projects

Blue Origin cancels second New Glenn launch, will try again on November 12th

Slow Ventures hosts a ‘finishing school’ to help founders learn to be fancy

Blue Origin cancels second New Glenn launch due to weather and cruise ship traffic

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.