Story perspectives
Major Vulnerability Exposes 1,000+ Businesses to Remote Attacks
10/13/2025
42 3
1 of 1
Story summary
- The zero-day vulnerability CVE-2025-11371 in Gladinet CentreStack and Triofox allows remote code execution via unauthenticated local file inclusion.
- Researchers from Huntress report that at least three companies have been targeted.
- Gladinet has informed customers and provides a workaround by disabling the temp handler in UploadDownloadProxy’s Web.config.
- No patch has been released, increasing the risk posed by the vulnerability.
- Gladinet's site says more than 1,000 businesses may be at risk.
