---
id: CVE-2025-11371
title: Gladinet CentreStack and TrioFox Local File Inclusion Flaw
summary: >-
  In the default installation and configuration of Gladinet CentreStack and
  TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows
  unintended disclosure of system files. Exploitation of this vulnerability has
  been obser…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: adp
vendor: Gladinet
product: CentreStack and TrioFox
affected:
  - centrestack_and_triofox <= 16.7.10368.56560
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-11-04T04:55:24.660911Z'
exploited: true
exploitAvailable: true
published: '2025-10-09'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:59:08.851Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-11371'
references:
  - url: >-
      https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw
tags:
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
epss: 0.92137
epssPercentile: 0.99819
kev: true
kevDateAdded: '2025-11-04'
kevDueDate: '2025-11-25'
kevRansomware: false
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/rxerium/CVE-2025-11371'
    - 'https://github.com/lap1nou/CVE-2025-11371'
    - 'https://github.com/NetVanguard-cmd/CVE-2025-11371'
  metasploit:
    - auxiliary/gather/gladinet_storage_path_traversal_cve_2025_11371
  nuclei:
    - CVE-2025-11371
  checkedAt: '2026-09-25T08:20:44.546Z'
ingestedAt: '2026-09-21T17:49:53.184Z'
---

## Overview

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. 

This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

## Affected

- `centrestack_and_triofox <= 16.7.10368.56560`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

If you currently utilize either CentreStack or TrioFox, please check your inbox for communication from Gladinet regarding a temporary mitigation while a patch is being developed.
