CVE-2025-14611CRITICAL 9.8CISA KEVEPSS p98.8%
CVE-2025-14611Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Gladinet / CentreStack and Triofox
Description
Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 50.95% probability of exploitation · percentile 98.8% · 2026-06-18T12:00:27Z |
| Published | 2025-12-12 |
| Last modified | 2025-12-16 |
CISA KEV entry
Added to KEV: 2025-12-15
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Hard-coded Credentialscwe-798 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerabilitykev-cve-2025-14611 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.