• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-gladinet-centrestack-cryptographic-flaw-in-rce-attacks/

Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks

BleepingComputer
·
Bill Toulas
·
Published Dec 11, 2025
·
Updated

Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and sharing. By leveraging the security issue, the attackers can obtain hardcoded cryptographic keys and achieve remote code execution, researchers warn. Although the new cryptographic vulnerability does not have an official identifier, Gladinet notified customers about it and advised them to update the products to the latest version, which, at the time of the communication, had been released on November 29. The company also provided customers with a set of indicators of compromise (IoCs), indicating that the issue was being exploited in the wild. Security researchers at managed cybersecurity platform Huntress are aware of at least nine organizations targeted in attacks leveraging the new vulnerability along with an older one tracked as CVE-2025-30406 - a local file inclusion flaw that allows a local attacker to access system files without authentication. Using the IoCs from Gladinet, Huntress researchers were able to determine where the flaw was and how threat actors are leveraging it. Huntress found that the issue stems from the custom implementation of the AES cryptographic algorithm in Gladinet CentreStack and Triofox, where the encryption key and Initialization Vector (IV) were hardcoded inside the GladCtrl64.dll file and could be easily obtained. Specifically, the key values we...

Read full article

Affected Software

2 affected components
Gladinet CentreStack
Gladinet Triofox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a cryptographic flaw in Gladinet CentreStack and Triofox products by hackers.

2

What security implications are discussed in this article?

The article highlights that attackers can exploit a vulnerability to obtain hardcoded cryptographic keys, leading to remote code execution (RCE) attacks.

3

What products or software are affected by the vulnerability?

The affected products are Gladinet CentreStack and Gladinet Triofox.

4

Is this vulnerability documented or known?

No, the vulnerability is described as undocumented and has been categorized as a zero-day exploit.

5

When was this security issue reported?

The security issue was reported on December 11, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203