CVE-2025-11371: Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability
Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
Other sources
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.
This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Gladinet CentreStack and Triofoxfrom your environment.Discontinue use or uninstall the product if vendor mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions for Gladinet CentreStack and Triofox to mitigate the unauthenticated local file inclusion vulnerability.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services when deploying or mitigating Gladinet CentreStack and Triofox instances.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11371?
CVE-2025-11371 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive system files.
How do I fix CVE-2025-11371?
To address CVE-2025-11371, ensure that Gladinet CentreStack and TrioFox are updated to versions beyond 16.7.10368.56560 which contain the necessary security patches.
Which products are affected by CVE-2025-11371?
CVE-2025-11371 affects Gladinet CentreStack and Gladinet TrioFox up to version 16.7.10368.56560.
Is there a workaround for CVE-2025-11371?
A temporary workaround for CVE-2025-11371 includes limiting access to the affected applications until they can be patched.
What are the risks of exploiting CVE-2025-11371?
Exploitation of CVE-2025-11371 can lead to unauthorized disclosure of sensitive system files, potentially compromising confidential information.