CVE-2025-14611 is a critical vulnerability affecting Gladinet CentreStack and Triofox versions prior to 16.12.10420.56791, stemming from the use of hardcoded AES cryptographic values. This flaw allows for unauthenticated arbitrary local file inclusion via specially crafted requests on publicly exposed endpoints. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no authentication or user interaction required, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited (CISA KEV) and has high community discussion, with Nuclei templates available for detection, indicating a significant and immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.12.10420.56791CPE matchmatch criteria | cpe:2.3:a:gladinet:centrestack:*:*:*:*:*:*:*:* | ||
< 16.12.10420.56791CPE matchmatch criteria | cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.