← Back to CVE List
Vulnerability Intelligence Report
Gladinet CentreStack and TrioFox Local File Inclusion Flaw

CVE-2025-11371

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:92.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-552 ↗CWE-552 Files or Directories Accessible to External Parties

Affected Products & Versions

Vendor Product Affected Versions
Gladinet CentreStack and TrioFox 0 <= 16.7.10368.56560 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
92.137%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHuntress Labs Inc. · Vendor · USA
Reserved2025-10-06T14:00:55
Published2025-10-09T16:50:49
Patch Date2025-10-09
Last Updated2026-09-21T16:59:08

LINK COPIED TO CLIPBOARD