Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Gladinet CentreStack and TrioFox Unauthenticated Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability allowing unauthenticated access to system files has been identified in Gladinet CentreStack and TrioFox. This issue affects all versions prior to and including 16.7.10368.56560. The vulnerability arises from the default installation and configuration of these products, which inadvertently permit the inclusion of local files. Exploitation of this flaw has been observed in the wild, with attackers retrieving sensitive information such as the machine key from the Web.config file, potentially leading to remote code execution.

Impact

Successful exploitation allows for unauthorized access to system files, with the potential to retrieve sensitive information such as the machine key, which can be used for remote code execution in conjunction with other vulnerabilities.

Remediation

To mitigate this vulnerability, it is recommended to disable the temp handler in the Web.config file for the UploadDownloadProxy component. This can be done by removing a specific line that points to the temp handler, which will prevent the vulnerability from being exploited until a patch is available.

Added: Oct 9, 2025, 5:37 PM
Updated: Nov 4, 2025, 6:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
0.8
exploitability
6.9
remediation
6.0
relevance
0.7
threat
9.3
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.