Active Exploitation of Gladinet CentreStack/Triofox Insecure Cryptography Vulnerability

Dec. 21, 2025, 7:01 p.m.

Description

A critical vulnerability in Gladinet's CentreStack and Triofox products has been discovered, involving hardcoded cryptographic keys in their AES implementation. This flaw allows potential access to the web.config file, enabling deserialization and remote code execution. Attackers are actively targeting this vulnerability across various organizations. The issue stems from static encryption keys derived from unchanging Chinese and Japanese text strings, allowing for decryption and creation of access tickets. Exploitation attempts have been observed across multiple sectors, with attackers using the vulnerability to obtain machine keys and perform viewstate deserialization attacks. Immediate updates to the latest version and machine key rotation are recommended for mitigation.

Date

  • Created: Dec. 11, 2025, 6:25 p.m.
  • Published: Dec. 11, 2025, 6:25 p.m.
  • Modified: Dec. 21, 2025, 7:01 p.m.

Indicators

  • 147.124.216.205

Attack Patterns

Additional Informations

  • Health
  • Technologies

Linked vulnerabilities