CVE-2025-11371 is an unauthenticated Local File Inclusion (LFI) flaw present in the default installations of Gladinet CentreStack and Triofox, impacting all versions up to and including 16.7.10368.56560. This vulnerability allows for the unintended disclosure of system files. With a CVSS score of 7.5 (HIGH), it is easily exploitable over the network without authentication or user interaction, leading to high confidentiality impact. This flaw is actively exploited in the wild, listed in CISA's KEV catalog, and has publicly available exploit modules in Metasploit and Nuclei templates, indicating significant community attention and a high FAUCET Risk Score of 100/100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.10.10408.56683CPE matchmatch criteria | cpe:2.3:a:gladinet:centrestack:*:*:*:*:*:*:*:* | ||
<= 16.7.10368.56560CPE matchmatch criteria | cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.