Skip to content
COOEY

EXPOSURES › CVE-2025-12480

CVE-2025-12480

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-11-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-12480 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Gladinet Triofox exposed initial setup pages post-completion, allowing unauthorized access.

Gladinet Triofox, a product from Gladinet, had an unpatched improper access control vulnerability that enabled attackers to access its initial setup pages even after the setup was complete. This exposed sensitive configuration data to unauthorized users.

Shame score — Unauthorized access to initial setup pages post-completion, leading to potential data exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.