Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14611

96
FAUCET Score

CVE-2025-14611 is a critical vulnerability affecting Gladinet CentreStack and Triofox versions prior to 16.12.10420.56791, stemming from the use of hardcoded AES cryptographic values. This flaw allows for unauthenticated arbitrary local file inclusion via specially crafted requests on publicly exposed endpoints. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no authentication or user interaction required, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited (CISA KEV) and has high community discussion, with Nuclei templates available for detection, indicating a significant and immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 16.12.10420.56791CPE matchmatch criteria
cpe:2.3:a:gladinet:centrestack:*:*:*:*:*:*:*:*
< 16.12.10420.56791CPE matchmatch criteria
cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
ATTACKED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
50.95%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Dec 15, 2025
Metasploit: Gladinet CentreStack/Triofox Access Ticket Forge · Dec 10, 2025
Nuclei: CVE-2025-14611 · Dec 17, 2025
This CVE's current EPSS score of 0.5095 is in the 97th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
huntress.com / blog/active-exploitation-gladinet-centrestack-triofox-insecure-cryptography-vulnerability
ExploitThird Party Advisory