CVE-2025-12480: Gladinet Triofox Improper Access Control Vulnerability
Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
Other sources
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gladinet/Triofoxto a version that resolves this vulnerability.Fixed in 16.7.10368.56560 - Remove
Remove
Gladinet/Triofoxfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12480?
CVE-2025-12480 has a high severity due to its improper access control vulnerability.
How do I fix CVE-2025-12480?
To fix CVE-2025-12480, upgrade to Triofox version 16.7.10368.56560 or later.
What are the risks associated with CVE-2025-12480?
The risks associated with CVE-2025-12480 include unauthorized access to sensitive setup pages.
Which versions of Triofox are affected by CVE-2025-12480?
Triofox versions prior to 16.7.10368.56560 are affected by CVE-2025-12480.
Is there a workaround for CVE-2025-12480?
There is no official workaround for CVE-2025-12480; an upgrade is recommended to mitigate the vulnerability.