References https://nvd.nist.gov/vuln/detail/CVE-2025-30406 https://www.huntress.com/blog/cve-2025-30406-critical-gladinet-centrestack-triofox-vulnerability-exploited-in-the-wild https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf https://www.centrestack.com/p/gce_latest_release.html https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30406 https://www.tenable.com/cve/CVE-2025-30406 https://blackpointcyber.com/blog/blog-racing-to-exploit-centrestacks-cve-2025-30406/ https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2025/CVE-2025-30406.yaml https://cve.imfht.com/detail/CVE-2025-30406 https://www.cybersecuritydive.com/news/attackers-exploit-zero-day-gladinet-centrestack-file-sharing/745407/
Related VulnerabilitiesCentreStack 本地文件包含漏洞(CVE-2025-11371)Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)PoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials(CVE-2025-14611)Gladinet CentreStack和Triofox AES加密硬编码漏洞导致任意文件包含及安全降级Gladinet CentreStack & TrioFox /storage/t.dn 目录遍历漏洞(CVE-2025-11371)PoCCVE-2025-30406: Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCEPoCCVE-2025-11371: Gladinet CentreStack & TrioFox - Local File InclusionGladinet CentreStack /portal/loginpage.aspx 代码执行漏洞(CVE-2025-30406)(CVE-2025-30406)Gladinet CentreStack反序列化漏洞