Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
History

Mon, 15 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-12-15T00:00:00+00:00', 'dueDate': '2026-01-05T00:00:00+00:00'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Gladinet
Gladinet centrestack
Gladinet triofox
Vendors & Products Gladinet
Gladinet centrestack
Gladinet triofox

Sat, 13 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
Title Gladinet CentreStack and TrioFox Hard Coded AES Keys
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Huntress

Published: 2025-12-12T21:01:13.116Z

Updated: 2025-12-15T23:20:23.517Z

Reserved: 2025-12-12T20:22:27.367Z

Link: CVE-2025-14611

cve-icon Vulnrichment

Updated: 2025-12-13T22:56:09.339Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-12-12T21:15:53.107

Modified: 2025-12-15T19:16:03.987

Link: CVE-2025-14611

cve-icon Redhat

No data.