CVE-2025-11371High· 7.5▾ Abyssal⚠ Exploited in the wildPoC availableIn the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been obser…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 41.3 · likelihood 18.4 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the CISA ADP record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Federal remediation due Nov 25, 2025
Last analysed / modified upstream
92%
3 GitHub repos · Metasploit ×1 · Nuclei ×1 (last check)
Added to the CISA catalog on Nov 4, 2025. Federal remediation due Nov 25, 2025. View catalog ↗
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.
This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
centrestack_and_triofox <= 16.7.10368.56560Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
If you currently utilize either CentreStack or TrioFox, please check your inbox for communication from Gladinet regarding a temporary mitigation while a patch is being developed.