Hackers exploited a vulnerability in Gladinet CentreStack's secure file-sharing software as a zero-day since March to breach storage servers Gladinet CentreStack is an enterprise file-sharing and access platform that turns on-premise file servers (like Windows servers with SMB shares) into secure, cloud-like file systems supporting remote access to internal file shares, file syncing and sharing, multi-tenant deployments, and integration with Active Directory. The company claims the product is used by thousands of businesses across 49 countries, including enterprises with Windows-based file servers, MSPs hosting file services for multiple clients, and various organizations that need cloud-like access without cloud migration. The flaw, tracked as CVE-2025-30406, is a deserialization vulnerability impacting Gladinet CentreStack versions up to 16.1.10296.56315. Exploitation in the wild has been observed since March 2025. The issue stems from using a hardcoded machineKey in the CentreStack portal's configuration (web.config). If an attacker knows this key, they can craft a malicious serialized payload that the server will trust and execute. According to the vendor's advisory, the improperly protected key secures ASP.NET ViewState, which, if forged, can allow attackers to bypass integrity checks, inject arbitrary serialized objects, and eventually execute code on the server. Gladinet released a security fix for CVE-2025-30406 on April 3, 2025, with versions 16.4.10315.56368, 16.3....
CentreStack RCE exploited as zero-day to breach file sharing servers
BleepingComputer
·Bill Toulas
·Published Apr 9, 2025
·Updated
Affected Software
5 affected components
Gladinet CentreStack=16.1.10296.56315
Gladinet CentreStack=16.4.10315.56368
Gladinet CentreStack=16.3.4763.56357
Gladinet CentreStack=15.12.434
Gladinet CentreStack=16.1.10296.56315
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability exploited in Gladinet CentreStack's file-sharing software leading to breaches of storage servers.
2
What security implications are discussed?
The article highlights that the vulnerability can allow unauthorized access and exploitation of sensitive file-sharing data.
3
What products or software are affected?
The affected software is Gladinet CentreStack, specifically versions 15.12.434 and 16.x series including 16.1.10296.56315, 16.3.4763.56357, and 16.4.10315.56368.
4
When was the vulnerability first exploited?
The vulnerability has been exploited since March as a zero-day threat.
5
How can organizations protect themselves from this vulnerability?
Organizations are advised to update to the latest versions of Gladinet CentreStack to mitigate the risks associated with this vulnerability.