Cybersecurity Chaos: Unpatched Flaw Leaves Gladinet Users Vulnerable!
Cybersecurity company Huntress has detected active exploitation of a zero-day vulnerability, CVE-2025-11371, affecting Gladinet CentreStack and TrioFox. This flaw, with a CVSS score of 6.1, allows unintended file disclosure. Users are advised to disable the “temp” handler to mitigate risks while waiting for a patch.

Hot Take:
Looks like the hackers have found yet another zero-day vulnerability to exploit, proving once again that software developers should spend less time dreaming up cool names like “Gladinet CentreStack” and “TrioFox,” and more time patching their products. Who knew that the digital foxes were the ones with the keys to the henhouse?
Key Points:
- Huntress has identified an unpatched vulnerability in Gladinet CentreStack and TrioFox.
- The zero-day flaw, CVE-2025-11371, has a CVSS score of 6.1.
- This bug allows unauthorized access to system files and potential remote code execution.
- Previous vulnerabilities, such as CVE-2025-30406, have already been exploited in the wild.
- Users are advised to disable a specific handler to mitigate the risk.
Already a member? Log in here