---
id: CVE-2025-14611
title: >-
  Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used
  hardcoded values for their implementation of the AES cryptoscheme
summary: >-
  Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used
  hardcoded values for their implementation of the AES cryptoscheme. This
  degrades security for public exposed endpoints that may make use of it and may
  offer arbitra…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
vendor: gladinet
product: centrestack
affected:
  - centrestack < 16.12.10420.56791
  - triofox < 16.12.10420.56791
patched:
  - centrestack 16.12.10420.56791
  - triofox 16.12.10420.56791
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14611'
references:
  - url: >-
      https://www.huntress.com/blog/active-exploitation-gladinet-centrestack-triofox-insecure-cryptography-vulnerability
    label: 5dacb0b8-2277-4717-899c-254586fe4912
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14611
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.53302
epssPercentile: 0.98958
kev: true
kevDateAdded: '2025-12-15'
kevDueDate: '2026-01-05'
kevRansomware: false
exploited: true
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/pl4tyz/CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit
  metasploit:
    - auxiliary/gather/gladinet_storage_access_ticket_forge
  nuclei:
    - CVE-2025-14611
  checkedAt: '2026-10-07T20:47:22.830Z'
exploitAvailable: true
ingestedAt: '2026-10-07T20:46:46.910Z'
---

## Overview

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

## Affected

- `centrestack < 16.12.10420.56791`
- `triofox < 16.12.10420.56791`

## Remediation

Upgrade past the affected range:

- `centrestack 16.12.10420.56791`
- `triofox 16.12.10420.56791`
