LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-14611: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 15, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-14611 to its Known Exploited Vulnerabilities catalog on Dec 15, 2025, with a federal patch deadline of Jan 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed…

This vulnerability affects Gladinet CentreStack and Triofox and arises from hardcoded cryptographic keys used in their AES implementation. It weakens protections on publicly reachable endpoints and can permit unauthenticated arbitrary local file inclusion via specially crafted requests.

How it works

The underlying weakness is CWE-798, the use of hard-coded credentials. Here the product embeds static keys for its AES scheme instead of deriving or loading them securely at runtime.

An attacker who reaches an exposed endpoint can use the known keys to bypass intended encryption controls. The same condition may allow a crafted request to retrieve arbitrary local files without authentication.

Am I affected? How to find it in your systems

CentreStack and Triofox are typically deployed as on-premises or cloud-hosted file synchronization and collaboration servers. Begin by inventorying every installation through configuration management databases, package managers, or network scans for the associated services.

Exact version checks and configuration details must be confirmed against the vendor advisory.

How to remediate

Apply the vendor-supplied update referenced in the advisory. After patching, restrict public exposure of the affected endpoints and enforce network controls that limit which addresses can reach the services.

If you can't patch immediately

Apply mitigations described by the vendor or discontinue use of the product if those mitigations are unavailable. Segment the affected systems so they are reachable only from trusted management networks. Deploy web-application firewall rules that block requests exhibiting local-file-inclusion patterns. Increase logging and alerting on the endpoints to detect anomalous unauthenticated access attempts.

If your data may have been exposed

Actively exploited vulnerabilities of this class have led to unauthorized access and subsequent breaches. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether related credentials or files have already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGladinet · CentreStack and Triofox
WeaknessCWE-798
Added to CISA KEVDec 15, 2025
Federal patch deadlineJan 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities