CVE-2025-14611
- EPSS 59.05%
- Veröffentlicht 12.12.2025 21:01:13
- Zuletzt bearbeitet 16.12.2025 13:48:02
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file...
CVE-2025-11371
- EPSS 73.12%
- Veröffentlicht 09.10.2025 16:50:49
- Zuletzt bearbeitet 05.11.2025 14:32:00
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wi...
CVE-2025-30406
- EPSS 85.88%
- Veröffentlicht 03.04.2025 00:00:00
- Zuletzt bearbeitet 05.11.2025 19:27:44
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the m...
CVE-2024-37782
- EPSS 0.07%
- Veröffentlicht 22.11.2024 18:15:17
- Zuletzt bearbeitet 27.11.2024 17:15:11
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.
CVE-2024-37783
- EPSS 0.12%
- Veröffentlicht 22.11.2024 18:15:17
- Zuletzt bearbeitet 22.11.2024 19:15:06
A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.
CVE-2023-26829
- EPSS 0.31%
- Veröffentlicht 31.03.2023 16:15:07
- Zuletzt bearbeitet 18.02.2025 17:15:15
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full...
CVE-2023-26830
- EPSS 0.22%
- Veröffentlicht 31.03.2023 16:15:07
- Zuletzt bearbeitet 18.02.2025 17:15:16
An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to the server.