The encryption technique used in Gladinet’s CentreStack and Triofox products for safe remote file access and sharing has a new, unreported weakness that hackers are taking advantage of.
Researchers caution that the attackers can gain hardcoded cryptographic keys and accomplish remote code execution by taking advantage of the security flaw.
Gladinet recommended clients to update their goods to the most recent version, which had been released on November 29 at the time of the message, despite the fact that the new cryptographic vulnerability lacks an official identification.
Additionally, the business gave clients a list of indicators of compromise (IoCs) that showed how the problem was being used in the real world.
At least nine organizations have been the target of attacks using the new vulnerability and an older one known as CVE-2025-30406, a local file inclusion flaw that enables a local attacker read more about Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
