• News/
  • https://www.bleepingcomputer.com/news/security/centrestack-rce-exploited-as-zero-day-to-breach-file-sharing-servers/

CentreStack RCE exploited as zero-day to breach file sharing servers

BleepingComputer
·
Bill Toulas
·
Published Apr 9, 2025
·
Updated

Hackers exploited a vulnerability in Gladinet CentreStack's secure file-sharing software as a zero-day since March to breach storage servers Gladinet CentreStack is an enterprise file-sharing and access platform that turns on-premise file servers (like Windows servers with SMB shares) into secure, cloud-like file systems supporting remote access to internal file shares, file syncing and sharing, multi-tenant deployments, and integration with Active Directory. The company claims the product is used by thousands of businesses across 49 countries, including enterprises with Windows-based file servers, MSPs hosting file services for multiple clients, and various organizations that need cloud-like access without cloud migration. The flaw, tracked as CVE-2025-30406, is a deserialization vulnerability impacting Gladinet CentreStack versions up to 16.1.10296.56315. Exploitation in the wild has been observed since March 2025. The issue stems from using a hardcoded machineKey in the CentreStack portal's configuration (web.config). If an attacker knows this key, they can craft a malicious serialized payload that the server will trust and execute. According to the vendor's advisory, the improperly protected key secures ASP.NET ViewState, which, if forged, can allow attackers to bypass integrity checks, inject arbitrary serialized objects, and eventually execute code on the server. Gladinet released a security fix for CVE-2025-30406 on April 3, 2025, with versions 16.4.10315.56368, 16.3....

Read full article

Affected Software

5 affected components
Gladinet CentreStack=16.1.10296.56315
Gladinet CentreStack=16.4.10315.56368
Gladinet CentreStack=16.3.4763.56357
Gladinet CentreStack=15.12.434
Gladinet CentreStack=16.1.10296.56315
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability exploited in Gladinet CentreStack's file-sharing software leading to breaches of storage servers.

2

What security implications are discussed?

The article highlights that the vulnerability can allow unauthorized access and exploitation of sensitive file-sharing data.

3

What products or software are affected?

The affected software is Gladinet CentreStack, specifically versions 15.12.434 and 16.x series including 16.1.10296.56315, 16.3.4763.56357, and 16.4.10315.56368.

4

When was the vulnerability first exploited?

The vulnerability has been exploited since March as a zero-day threat.

5

How can organizations protect themselves from this vulnerability?

Organizations are advised to update to the latest versions of Gladinet CentreStack to mitigate the risks associated with this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203