S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 19, 2025

CVE-2025-14611 Scanner

CVE-2025-14611 Scanner - Hard-Coded Credentials vulnerability in Gladinet CentreStack & Triofox

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-14611
7.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CentreStack and TrioFoxby Gladinet
AFFECTED< 16.12.10420.56791SAFE ✓≥ 16.12.10420.56791
Updated Aug 22, 2026View on NVD →
Detail

Gladinet CentreStack and Triofox are widely used by enterprises for cloud storage and sharing solutions. These platforms offer seamless integration with cloud services, allowing businesses to manage their data efficiently. The systems are used by both small and large organizations across various industries, including healthcare, finance, and education. Their primary purpose is to provide a secure environment for storing and sharing files. They offer features like centralized management, access controls, and collaboration capabilities. These products are vital tools for maintaining productivity while ensuring data security and compliance with industry standards.

The hard-coded credentials vulnerability in Gladinet CentreStack and Triofox arises from the use of fixed cryptographic keys. This flaw allows unauthorized users to bypass security mechanisms by exploiting static AES cryptoscheme values. When attackers gain access, they can perform arbitrary local file inclusions without needing authentication. As a result, the vulnerability can lead to data exposure, unauthorized data manipulation, and potentially full system compromise. This type of vulnerability is critical because it undermines one of the fundamental security controlsauthentication and access management.

The vulnerability details involve the improper handling and storage of cryptographic keys within the software. Instead of utilizing dynamic keys, the software employs hard-coded keys that can be easily extracted and exploited. The vulnerable endpoints typically include URL paths associated with authentication and file handling processes. Attackers manipulate these endpoints using the compromised keys to gain unauthorized access. The critical aspect of this vulnerability lies in the use of insecure cryptographic practices which create a significant security hole in the system.

The exploitation of this vulnerability can have severe consequences, including unauthorized data access and system control. Attackers could potentially expose sensitive corporate and personal data, resulting in data leaks and privacy violations. Furthermore, successful exploitation allows attackers to execute arbitrary code, leading to full system takeover. Organizations affected by this exploit could face financial losses, reputational damage, and legal consequences due to data breaches and non-compliance with data protection regulations.

REFERENCES

Solution Advice
  • Update the software to version 16.12.10420.56791 or later to mitigate the vulnerability.
  • Implement dynamic cryptographic key management to replace hardcoded values.
  • Conduct regular security audits to identify and fix similar vulnerabilities promptly.
  • Ensure adherence to industry standards for cryptographic practices in all secure applications.
  • Educate the IT and development team about secure coding practices to prevent hardcoding of sensitive information.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.