Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gladinet Patches Exploited CentreStack Vulnerability

Gladinet Patches Exploited CentreStack Vulnerability

Posted on October 17, 2025October 17, 2025 By CWS

Gladinet this week launched patches for a CentreStack vulnerability that has been exploited within the wild since a minimum of late September.

Tracked as CVE-2025-11371, the difficulty is described as an unauthenticated file inclusion bug that enables attackers to retrieve system recordsdata.

Impacting the default configurations of Gladinet’s CentreStack and TrioFox merchandise, the safety defect was exploited within the wild as a zero-day to retrieve a ‘machineKey’ cryptographic key from a configuration file and execute arbitrary code remotely.

To realize distant code execution, nevertheless, the attackers exploited a ViewState deserialization vulnerability, cybersecurity agency Huntress explains.

The ViewState deserialization problem was beforehand abused in assaults exploiting CVE-2025-30406, a critical-severity CentreStack and Triofox flaw rooted within the presence of hardcoded keys within the functions’ configuration recordsdata.

Armed with a hardcoded machineKey, an attacker may bypass ASPX ViewState protections and execute arbitrary code remotely with the privileges of the IIS utility pool consumer. Profitable exploitation of the difficulty may enable attackers to take full management of a susceptible system.

Gladinet patched CVE-2025-30406 in April by updating one of many configuration recordsdata containing the machineKey and eradicating the important thing from one other.

As a part of the contemporary assaults flagged by Huntress, risk actors are exploiting CVE-2025-11371 to retrieve the configuration file containing the machineKey, which permits them to carry out a deserialization assault to execute instructions on the susceptible system.Commercial. Scroll to proceed studying.

Gladinet resolved the newly found vulnerability in CentreStack model 16.10.10408.56683. Given the flaw’s in-the-wild exploitation, organizations and finish customers are suggested to use the patches as quickly as attainable.

CentreStack is a self-hosted, on-premise cloud file server that gives organizations with safe file sharing capabilities. It may be deployed by MSPs for his or her shoppers and built-in with current infrastructure.

Associated: In Different Information: Gladinet Flaw Exploitation, Assaults on ICS Honeypot, ClayRat Adware

Associated: Organizations Warned of Exploited Adobe AEM Varieties Vulnerability

Associated: Cisco Routers Hacked for Rootkit Deployment

Associated: SAP Patches Essential Vulnerabilities in NetWeaver, Print Service, SRM

Security Week News Tags:CentreStack, Exploited, Gladinet, Patches, Vulnerability

Post navigation

Previous Post: F5 Released Security Updates Covering Multiple Products Following Recent Hack
Next Post: Vulnerabilities Allow Disruption of Phoenix Contact UPS Devices

Related Posts

13-Year-Old RCE Flaw Found in Apache ActiveMQ 13-Year-Old RCE Flaw Found in Apache ActiveMQ Security Week News
DeFi Protocol Balancer Starts Recovering Funds Stolen in 8 Million Heist DeFi Protocol Balancer Starts Recovering Funds Stolen in $128 Million Heist Security Week News
Deutsche Bahn Faces Major DDoS Attack Disruption Deutsche Bahn Faces Major DDoS Attack Disruption Security Week News
Google Chrome 148 Updates Address Critical Security Flaws Google Chrome 148 Updates Address Critical Security Flaws Security Week News
Navia Data Breach Affects Millions Navia Data Breach Affects Millions Security Week News
Obsidian Security Secures M, Hits .1B Valuation Obsidian Security Secures $85M, Hits $1.1B Valuation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark