References https://nvd.nist.gov/vuln/detail/CVE-2025-14611 https://www.cvedetails.com/cve/CVE-2025-14611/ https://www.rapid7.com/db/vulnerabilities/gladinet-centrestack-cve-2025-14611/ https://www.huntress.com/blog/active-exploitation-gladinet-centrestack-triofox-insecure-cryptography-vulnerability https://horizon3.ai/attack-research/vulnerabilities/cve-2025-14611/ https://www.cve.org/CVERecord?id=CVE-2025-14611 https://thehackernews.com/2025/12/hard-coded-gladinet-keys-let-attackers.html https://www.tenable.com/plugins/was/115078 https://fortiguard.fortinet.com/threat-signal-report/6303 https://github.com/advisories/GHSA-j7r7-3wrm-f59w
Related VulnerabilitiesCentreStack 本地文件包含漏洞(CVE-2025-11371)Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)PoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded CredentialsPoCCVE-2025-12480: Triofox - Improper Access Control(CVE-2025-12480)Triofox初始设置页面访问控制漏洞Gladinet CentreStack & TrioFox /storage/t.dn 目录遍历漏洞(CVE-2025-11371)PoCCVE-2025-30406: Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCEPoCCVE-2025-11371: Gladinet CentreStack & TrioFox - Local File InclusionGladinet CentreStack /portal/loginpage.aspx 代码执行漏洞(CVE-2025-30406)CentreStack 存在反序列化漏洞(CVE-2025-30406)(CVE-2025-30406)Gladinet CentreStack反序列化漏洞