CVE-2026-8359
- EPSS 0.28%
- Veröffentlicht 27.05.2026 19:49:18
- Zuletzt bearbeitet 29.05.2026 20:26:29
When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that modul...
CVE-2026-8360
- EPSS 0.28%
- Veröffentlicht 27.05.2026 19:47:29
- Zuletzt bearbeitet 29.05.2026 20:26:29
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The re...
CVE-2026-8361
- EPSS 0.35%
- Veröffentlicht 27.05.2026 19:44:38
- Zuletzt bearbeitet 29.05.2026 20:26:29
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
CVE-2026-8362
- EPSS 0.32%
- Veröffentlicht 27.05.2026 19:42:08
- Zuletzt bearbeitet 29.05.2026 20:26:29
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
CVE-2026-8363
- EPSS 0.34%
- Veröffentlicht 27.05.2026 19:40:33
- Zuletzt bearbeitet 29.05.2026 20:26:29
A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
CVE-2026-8364
- EPSS 0.31%
- Veröffentlicht 27.05.2026 19:38:01
- Zuletzt bearbeitet 29.05.2026 20:26:29
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.
CVE-2025-14611
- EPSS 50.95%
- Veröffentlicht 12.12.2025 21:01:13
- Zuletzt bearbeitet 16.12.2025 13:48:02
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file...
CVE-2025-12480
- EPSS 90.36%
- Veröffentlicht 10.11.2025 14:20:40
- Zuletzt bearbeitet 14.11.2025 02:00:02
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
CVE-2025-11371
- EPSS 92.09%
- Veröffentlicht 09.10.2025 16:50:49
- Zuletzt bearbeitet 05.11.2025 14:32:00
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wi...