Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Wireshark Flaws Allow Code Execution via Malformed
May 1, 2026
Anthropic Launches Claude Security Beta for Enterprise
May 1, 2026
Human-Centric
Beyond the Click: A Human-Centric Approach to Phishing Defense
April 30, 2026
Home/Vulnerabilities/CISA Warns: Gladinet CentreStack, Vulnerability Attack
Vulnerabilities

CISA Warns: Gladinet CentreStack, Vulnerability Attack

CISA Warns: Gladinet CentreStack, Vulnerability Attack CISA just dropped a critical warning, and it’s a pretty serious one. They’re talking about a hardcoded cryptographic key...

Marcus Rodriguez
Marcus Rodriguez
January 1, 2026 2 Min Read
30 0

CISA Warns: Gladinet CentreStack, Vulnerability Attack

CISA just dropped a critical warning, and it’s a pretty serious one. They’re talking about a hardcoded cryptographic key vulnerability that’s currently affecting Gladinet CentreStack and Triofox – you know, those file management solutions.

The vulnerability, tracked as CVE-2025-14611, poses significant risks to organizations using these widely deployed enterprise file-sharing platforms.

The flaw lies in how Gladinet CentreStack and Triofox implement their AES cryptographic scheme.

Attackers can exploit hardcoded cryptographic keys embedded in applications to bypass authentication and gain unauthorized access to sensitive systems.

Authentication Bypass and File Inclusion Risks

The vulnerability affects publicly exposed endpoints, making them accessible to remote threat actors without requiring user credentials.

Most critically, successful exploitation enables arbitrary local file inclusion attacks. By crafting especially malicious requests, attackers can retrieve sensitive files from affected systems.

Field Details
CVE ID CVE-2025-14611
Vulnerability Title Gladinet CentreStack and Triofox Hardcoded Cryptographic Key Vulnerability
Affected Products Gladinet CentreStack, Triofox
Vulnerability Type Hardcoded Cryptographic Keys (CWE-798)
Attack Vector Network-based, unauthenticated access

Exposing confidential business documents, customer data, and system configuration files. The vulnerability carries significant implications for enterprise security posture.

Organizations relying on Gladinet CentreStack or Triofox for secure file collaboration face potential data exfiltration risks.

The lack of authentication requirements substantially widens the attack surface, allowing adversaries to target these systems directly from the internet.

CISA classified this issue as CWE-798, underscoring the risks of hard-coded credentials in cryptographic implementations.

This weakness undermines the fundamental security architecture of file-sharing solutions. These depend on encryption to protect sensitive information during transmission and storage.

CISA has set an immediate action deadline, with the remediation due date on January 5, 2026. Organizations should prioritize the following steps:

Apply all security patches and vendor-provided mitigations immediately. Review CISA’s BOD 22-01 guidance for cloud services to ensure compliance with federal security requirements.

For organizations unable to deploy mitigations, CISA recommends discontinuing use of affected products. Security teams should conduct thorough audits of their Gladinet CentreStack and Triofox deployments to identify potential exposures.

Network administrators should implement additional access controls and monitor these systems for suspicious activity. Organizations should contact their vendors for available patches and security updates.

Implement enhanced monitoring on file-sharing infrastructure, and consider deploying additional network segmentation to limit exposure from compromised endpoints.

As threat actors increasingly target enterprise collaboration tools, swift action remains essential for protecting organizational data and maintaining security integrity.

Tags:

AttackCryptoCVEExploitPatchSecurityThreatUpdateVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Detect Cisco Email Gateway 0-Day Exploits: Tool…

Next Post

Hertz Data Breach: Customer Personal Data Stolen by

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Targeted Large-Scale Campaign Attacking U.S. Organizations with
April 30, 2026
Popular Python Package ‘lightning’ Hacked in Supply Chain
April 30, 2026
FBI & CISA Release Zero Trust Guide for Released Principles
April 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Sarah simpson
Sarah simpson
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us