⤷ Title: Exploited Zero-Day: Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11371 #Gladinet #lfi #local file inclusion #rce #Triofox #ViewState Deserialization #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11371 #Gladinet #lfi #local file inclusion #rce #Triofox #ViewState Deserialization #zero_day
Daily CyberSecurity
Exploited Zero-Day: Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
A Zero-Day LFI flaw (CVE-2025-11371) in Gladinet/Triofox is being actively exploited. Attackers retrieve the Web.config machine key to chain into an unauthenticated RCE exploit.
⤷ Title: Exploited Zero-Day: Critical Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 03:01:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_11371 #Gladinet #Huntress #LFI #Local File Inclusion #RCE #Triofox #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 03:01:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_11371 #Gladinet #Huntress #LFI #Local File Inclusion #RCE #Triofox #zero_day
Penetration Testing Tools
Exploited Zero-Day: Critical Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
Huntress discovered active exploitation of an unpatched LFI zero-day (CVE-2025-11371) in Gladinet/Triofox. Attackers chain the flaw to steal the machine key and achieve RCE without authentication.
⤷ Title: CISA KEV Alert: Two Critical Flaws Under Active Exploitation, Including Gladinet LFI/RCE and CWP Admin Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 00:37:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #Control Web Panel #CVE_2025_11371 #Gladinet #local file inclusion #rce #Triofox
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 00:37:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #Control Web Panel #CVE_2025_11371 #Gladinet #local file inclusion #rce #Triofox
Daily CyberSecurity
CISA KEV Alert: Two Critical Flaws Under Active Exploitation, Including Gladinet LFI/RCE and CWP Admin Takeover
CISA added two critical, actively exploited flaws to its KEV Catalog: Gladinet LFI (CVE-2025-11371) risks RCE via machine key theft, and CWP RCE (CVE-2025-48703) allows unauthenticated admin takeover.
⤷ Title: Critical Triofox Zero-Day (CVE-2025-12480) Under Active Exploit: Host Header Bypass Allows Unauthenticated Admin Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 02:01:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Gladinet #Host Header Spoofing #Mandiant #Triofox #UNC6485 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 02:01:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Gladinet #Host Header Spoofing #Mandiant #Triofox #UNC6485 #zero_day
Daily CyberSecurity
Critical Triofox Zero-Day (CVE-2025-12480) Under Active Exploit: Host Header Bypass Allows Unauthenticated Admin Takeover
Mandiant exposed UNC6485 exploiting a Triofox zero-day (CVE-2025-12480). The critical flaw allows unauthenticated admin takeover by spoofing the HTTP Host header to bypass authentication checks.
⤷ Title: Mandiant: Triofox Zero-Day Exploited to Gain SYSTEM Access via Antivirus Feature
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 02:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12480 #Gladinet #HTTPHostHeader #Mandiant #RCE #Triofox #UNC6485 #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 02:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12480 #Gladinet #HTTPHostHeader #Mandiant #RCE #Triofox #UNC6485 #zeroday
Penetration Testing Tools
Mandiant: Triofox Zero-Day Exploited to Gain SYSTEM Access via Antivirus Feature
A critical Triofox zero-day (CVE-2025-12480) was exploited by UNC6485. Attackers bypassed auth via Host header, created an admin, and ran code as SYSTEM via the AV check.
⤷ Title: PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
Penetration Testing Tools
PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
Gladinet is facing fresh trouble once again: vulnerabilities have been uncovered in its CentreStack and Triofox products stemming