Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
History

Sat, 13 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
Title Gladinet CentreStack and TrioFox Hard Coded AES Keys
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Huntress

Published: 2025-12-12T21:01:13.116Z

Updated: 2025-12-14T04:56:08.802Z

Reserved: 2025-12-12T20:22:27.367Z

Link: CVE-2025-14611

cve-icon Vulnrichment

Updated: 2025-12-13T22:56:09.339Z

cve-icon NVD

Status : Received

Published: 2025-12-12T21:15:53.107

Modified: 2025-12-13T23:15:51.873

Link: CVE-2025-14611

cve-icon Redhat

No data.