Security
Loading…

CVE-2025-14611

UNKNOWNKnown Exploited
Description

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

Timeline
Published:December 15th, 2025 12:00 AM
Last modified:December 15th, 2025 12:00 AM
Added to KEV:December 15th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Gladinet

Products

CentreStack and Triofox
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute