Drooid Logo
Back to today’s briefing

Story perspectives

Critical Gladinet Vulnerability Exploited for Remote Access

11/12/2025

27 6 Full Breakdown

1 of 1

Story summary
  • A critical vulnerability, CVE-2025-12480, in Gladinet's Triofox is being exploited by UNC6485 since August 2025.
  • Attackers used the antivirus feature to bypass security and gain remote access.
  • The flaw has a CVSS score of 9.1, and it was introduced in April 2025 and patched in July 2025.
  • Mandiant researchers report attackers created a new admin account to upload scripts.
  • Organizations should apply the latest patches and monitor for unusual activity.