Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability

The Hacker News by The Hacker News
April 15, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Apr 15, 2025Ravie LakshmananVulnerability / Endpoint Security

A recently disclosed security flaw in Gladinet CentreStack also impacts its Triofox remote access and collaboration solution, according to Huntress, with seven different organizations compromised to date.

Tracked as CVE-2025-30406 (CVSS score: 9.0), the vulnerability refers to the use of a hard-coded cryptographic key that could expose internet-accessible servers to remote code execution attacks.

It has been addressed in CentreStack version 16.4.10315.56368 released on April 3, 2025. The vulnerability is said to have been exploited as a zero-day in March 2025, although the exact nature of the attacks is unknown.

Now, according to Huntress, the weakness also affects Gladinet Triofox up to version 16.4.10317.56372.

Cybersecurity

“By default, previous versions of the Triofox software have the same hardcoded cryptographic keys in their configuration file, and can be easily abused for remote code execution,” John Hammond, principal cybersecurity researcher at Huntress, said in a report.

Gladinet's Triofox and CentreStack

Telemetry data gathered from its partner base has revealed that the CentreStack software is installed on about 120 endpoints and that seven unique organizations were affected by the exploitation of the vulnerability.

The earliest sign of compromise dates back to April 11, 2025, 16:59:44 UTC. The attackers have been observed leveraging the flaw to download and sideload a DLL using an encoded PowerShell script, an approach seen in recent attacks using the CrushFTP flaw, followed by conducting lateral movement and installing MeshCentral for remote access.

Huntress also said the attackers have been identified as running Impacket PowerShell commands to perform various enumeration commands and install MeshAgent. That said, the exact scale and the end goal of the campaigns are currently unknown.

In light of active exploitation, it’s essential that users of Gladinet CentreStack and Triofox update their instances to the latest version to safeguard against potential risks.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Ericsson reports first quarter results 2025

Ericsson reports first quarter results 2025

Recommended.

Current SaaS delivery model a risk management nightmare, says CISO | Computer Weekly

Current SaaS delivery model a risk management nightmare, says CISO | Computer Weekly

April 30, 2025
Actively managed ETFs hit  trillion milestone: Why tariff uncertainty may spark more growth

Actively managed ETFs hit $1 trillion milestone: Why tariff uncertainty may spark more growth

April 4, 2025

Trending.

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

July 18, 2025
Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

September 4, 2025
Wesco Declares Quarterly Dividend on Common Stock

Wesco Declares Quarterly Dividend on Common Stock

December 1, 2025
HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

October 24, 2025
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

March 10, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio