<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Gladinet</title><description>Actively exploited vulnerabilities affecting Gladinet products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/gladinet.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-14611 — Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-14611</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-14611</guid><description>Gladinet CentreStack and Triofox ship with hardcoded AES cryptographic keys, meaning any attacker who knows those keys — and they are not secret once discovered — can craft malicious requests against publicly exposed endpoints without needing any credentials. The practical result is unauthenticated local file inclusion, which allows attackers to read arbitrary files on the server. Any organization running these products on an internet-facing system is directly at risk.</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate><category>Gladinet</category><category>CentreStack and Triofox</category></item><item><title>CVE-2025-12480 — Gladinet Triofox Improper Access Control Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-12480</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-12480</guid><description>Gladinet Triofox, a file-sharing and collaboration platform, fails to properly restrict access to its initial setup pages after initial configuration is complete. This means an attacker could reach setup interfaces that should be locked down on a live system, potentially allowing unauthorized reconfiguration or takeover. Because setup pages typically carry elevated privileges and trust, exposure of these pages on a production system represents a serious risk of unauthorized access or system compromise.</description><pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate><category>Gladinet</category><category>Triofox</category></item><item><title>CVE-2025-11371 — Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-11371</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-11371</guid><description>Gladinet CentreStack and Triofox, which are file-sharing and remote access platforms used in enterprise environments, contain a vulnerability that exposes system files to unauthorized external parties. This means attackers could access sensitive files or directories on the server without proper authorization, potentially exposing credentials, configuration data, or other critical information that could enable further compromise of the environment.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><category>Gladinet</category><category>CentreStack and Triofox</category></item></channel></rss>