Skip to content
COOEY

EXPOSURES › CVE-2025-14611

CVE-2025-14611

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-14611 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Gladinet's CentreStack and Triofox had a hardcoded AES key vulnerability exploited in the wild

Gladinet CentreStack and Triofox, used by DIB, had a hardcoded AES key vulnerability that was actively exploited, potentially allowing unauthorized access to data.

Shame score — Highly avoidable and actively exploited cryptographic vulnerability

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.