CVE-2025-11371
Gladinet CentreStack vulnerability analysis and mitigation

Overview

CVE-2025-11371 is an unauthenticated Local File Inclusion (LFI) vulnerability affecting Gladinet CentreStack and TrioFox file-sharing and remote access platforms. The vulnerability was discovered in September 2025 and affects all versions prior to and including 16.7.10368.56560. The flaw allows unintended disclosure of system files without authentication in the default installation and configuration (Huntress Blog, Help Net Security).

Technical details

The vulnerability exists in the GladinetStorage.TempDownload function within GSUploadDownloadProxy.dll, which handles requests to the /storage/t.dn endpoint. Because the application runs as NT AUTHORITY\SYSTEM, attackers can use directory traversal characters (..) to retrieve any file relative to C:\Windows\Temp\glad_temp. The vulnerability has a CVSS 3.1 base score of 6.2 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (Huntress Blog, Hacker News).

Impact

The vulnerability allows attackers to access any file on the file system remotely without authentication. Specifically, attackers can retrieve the machine key from the application's Web.config file, which can then be used to perform remote code execution via ViewState deserialization. This creates a chain of exploitation that could lead to complete system compromise (Help Net Security, Hacker News).

Mitigation and workarounds

On October 14, 2025, Gladinet released version 16.10.10408.56683 of CentreStack, which includes a fix for the vulnerability. As an immediate workaround, users can disable the temp handler within the Web.config file located at C:\Program Files (x86)\Gladinet Cloud Enterprise\UploadDownloadProxy\Web.config. While this will impact some platform functionality, it prevents exploitation until the patch can be applied (Huntress Blog, Help Net Security).

Additional resources


SourceThis report was generated using AI

Related Gladinet CentreStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-30406CRITICAL9.8
  • Gladinet CentreStackGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
YesYesApr 03, 2025
CVE-2024-37782CRITICAL9.8
  • Gladinet CentreStackGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoNoNov 22, 2024
CVE-2023-26829CRITICAL9.8
  • Gladinet CentreStackGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesMar 31, 2023
CVE-2023-26830HIGH7.2
  • Gladinet CentreStackGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesMar 31, 2023
CVE-2025-11371MEDIUM6.2
  • Gladinet CentreStackGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesOct 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management