Vulnerability Intelligence Report
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
CVE-2025-11371
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:92.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-552 ↗CWE-552 Files or Directories Accessible to External Parties
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Gladinet | CentreStack and TrioFox | 0 <= 16.7.10368.56560 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
92.137%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Huntress Labs Inc. · Vendor · USA |
| Reserved | 2025-10-06T14:00:55 |
| Published | 2025-10-09T16:50:49 |
| Patch Date | 2025-10-09 |
| Last Updated | 2026-09-21T16:59:08 |
Community Chatter & Buzz