CVE-2025-11371HIGH 7.5CISA KEVEPSS p99.8%

CVE-2025-11371Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

Gladinet / CentreStack and Triofox

Description

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.

Scoring

CVSS 3.17.5 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS92.09% probability of exploitation · percentile 99.8% · 2026-06-17T12:03:21Z
Published2025-10-09
Last modified2025-11-05

CISA KEV entry

Added to KEV: 2025-11-04

Underlying weaknesses· 1

CWE-552

References

  1. https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw
  2. https://www.centrestack.com/p/gce_latest_release.html
  3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-11371

1

TypeTargetConfidenceTier
WeaknessFiles or Directories Accessible to External Partiescwe-5520%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryGladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerabilitykev-cve-2025-113710%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
CVE
Gladinet Triofox Improper Access Control Vulnerability
CVE
Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
CVE
Draytek VigorConnect Path Traversal Vulnerability
CVE
Srimax Output Messenger Directory Traversal Vulnerability
CVE
CVE-2026-22557
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.