Experts warn Gladinet file sharing tool flaw prompts dangerous cyberattacks – and there’s no patch

  • Gladinet CentreStack/Triofox have a zero-day vulnerability
  • The flaw (CVE-2025-11371) enables remote code execution
  • Users should apply mitigation as no patch is available

Secure file sharing and remote access solutions developed by Gladinet are reportedly carrying a zero-day vulnerability that is being abused to remotely execute malicious code (RCE), researchers are saying.

Since the zero-days in Gladinet CentreStack and Triofox are being actively exploited, and there is no patch available yet, users are urged to apply the available mitigation as soon as possible.

Recently, security researchers from Huntress were notified of a successful exploitation of a previously undocumented vulnerability. After reaching out to Gladinet, Huntress learned that the company was already aware of the flaw, and was in touch with a couple of victims in an attempt to minimize the damage.

Three victims so far

The flaw is described as an “unauthenticated local file inclusion vulnerability that allows threat actors to retrieve machine keys from the application Web.config file.” It is now tracked as CVE-2025-11371, and has a severity score of 6.2/10 (medium).

Don’t let the relatively low rating trick you – this is a dangerous flaw which enables RCE. According to Huntress, three companies have so far fallen victim to unnamed attackers, and given there’s no patch yet – that number could rise significantly.

CentreStack is a B2B file sharing solution that lets employees access company files remotely through mapped drives, mobile apps, or browsers, without migrating everything to public cloud services like Dropbox or Google Drive.

Triofox, on the other hand, is a cloud-enablement platform for file servers that provides VPN-less remote access with Active Directory integration, version control, and secure file sharing.

Gladinet allegedly already notified its customers about the flaw and is actively engaged in helping them minimize the risk, so businesses who read their supplier correspondence should be fine.

If you haven’t read your emails yet, you can also check the Huntress blog for details on how to stay safe. We don’t know how many businesses could be at risk but according to Gladinet’s website, it’s at least 1,000.

Via The Register

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Samsung brings a generative AI-powered Bixby to its TVs

Samsung is rolling out new conversational AI across its 2025 TVs that lets users ask questions about what’s on the screen and beyond it....

Snapchat is letting subscribers revive their 2D Bitmojis

The real 2D Bitmoji’s aren’t coming back, but the new Comic filter option is a close enough resemblance. Snapchat is bringing its 2D Bitmoji user...

Lumines Arise is an almost perfect zen puzzle game

With Tetris Effect, designer Tetsuya Mizuguchi and his team at Enhance, Inc. managed to make something old feel new. There are few things as...

Wyze’s new scale measures segmented body composition with a retractable handle

The retractable handle doubles the number of electrodes the smart scale uses to analyze your body composition. | Image: Wyze Wyze has announced its first...

The iPad Pro at 10: a decade of unrealized potential

The theory of the iPad has always been simple: size matters. Even in its very first public debut in 2010, the iPad was mostly...

Extreme smart home makeover

The best time to make your home smart is at the very beginning. Whether you're building from scratch, renovating, or just moving in, a...

Sandisk’s new 1TB USB-C SSD is so small you never need to take it out

Sandisk has released what it says is the world’s smallest 1TB USB-C flash drive, one tiny enough to plug into a laptop and never...

The LG G5 takes OLED performance to another level

Specular highlights on the G5 are bright and radiant. LG OLEDs are consistently some of the best TVs you can get, and I've lost count...

The 30 best gift ideas for mom this holiday season

Your mom deserves the best, and we're going to help you get them something special. The right gift can make family or friend time...

The Morning After: Is the Apple Watch SE 3 the best smartwatch for (almost) everyone?

Apple’s entry-level smartwatch has improved so much it delivers an experience comparable to pricier Apple Watches. The most important upgrades in the SE 3...