Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

Funksec Ransomware Decryptor was published for free after the group was dormant

Skechers make kids shoes with hidden air tag compartments

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Gladinet’s Triofox and Centrestack under aggressive exploitation through critical RCE vulnerabilities
Identity

Gladinet’s Triofox and Centrestack under aggressive exploitation through critical RCE vulnerabilities

userBy userApril 15, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 15, 2025Ravi LakshmananVulnerability/Endpoint Security

Critical RCE Vulnerabilities

According to Huntress, the security flaws recently revealed on Gladinet Centrestack have also affected Trifox’s remote access and collaboration solutions, which have compromised seven different organizations to date.

A vulnerability tracked as CVE-2025-30406 (CVSS score: 9.0) refers to the use of hard-coded encryption keys that allow Internet-accessible servers to be exposed to remote code execution attacks.

This is addressed in Centrestack version 16.4.10315.56368, released on April 3, 2025. The vulnerability is said to have been misused as a zero day in March 2025, but the exact nature of the attack is unknown.

Currently, according to Huntress, the weaknesses have also affected Gladinet Triofox up to version 16.4.10317.56372.

Cybersecurity

“By default, previous versions of Triofox software have the same hard-coded encryption key in their configuration files, allowing them to easily abuse remote code execution,” says John Hammond, Huntress’ chief cybersecurity researcher, in a report.

Gladinet's Triofox and Centrestack

Telemetry data collected from the partner base revealed that Centrestack software was installed on approximately 120 endpoints, with seven unique organizations being affected by vulnerability exploitation.

The oldest signs of compromise date back to 11 April 2025 at 16:59:44 UTC. It has been observed that attackers are exploiting flaws to download and sideload DLLs using encoded PowerShell scripts. This is an approach seen in a recent attack using a flaw in CrushFTP, then performs lateral movement and installs MeshCentral for remote access.

Huntress also said that the attacker has been identified as running in-packet PowerShell commands to install Meshagent by running various enumeration commands. That said, the exact scale and ultimate goal of the campaign is currently unknown.

In light of aggressive exploitation, it is essential for Gladinet Centrestack and Triofox users to update their instances to the latest version to prevent potential risks.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMeta resumes EU AI training using public user data after regulator approval
Next Article Harvard University faces $2.3 billion in funding, contrary to Trump’s demands | Education News
user
  • Website

Related Posts

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

July 30, 2025

Funksec Ransomware Decryptor was published for free after the group was dormant

July 30, 2025

Enabling remote hijacking via critical duffer camera defect ONVIF and file upload exploit

July 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

Funksec Ransomware Decryptor was published for free after the group was dormant

Skechers make kids shoes with hidden air tag compartments

2 How Uc Berkeley Dropout raised $28 million for AI Marketing Automation Startup

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

TwinH Transforms Belgian Student Life: Hendrik’s Journey to Secure Digital Identity

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.