The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether your business uses Gladinet CentreStack and/or TrioFox and whether they are reachable from the network (internet, remote access gateways, or shared networks).
Verify your installed version; determine whether it is at or below 16.7.10368.56560 (affected) and confirm whether you have already upgraded beyond it.
Upgrade CentreStack to 16.10.10408.56683 or later (and apply the equivalent vendor guidance for TrioFox if provided), following your vendor’s upgrade steps.
If you cannot patch immediately, follow Gladinet’s temporary mitigation instructions and reduce exposure (e.g., block public access / restrict network paths) until patched.
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.
This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560
In plain language
Written by AI from the record
Gladinet CentreStack and TrioFox have a flaw that can let an attacker read sensitive files from the server without needing a login—so most small businesses using these products should treat it as urgent and upgrade right away if exposed.
Unauthenticated Local File Inclusion (CWE-552) in Gladinet CentreStack and TrioFox allows an attacker to read arbitrary local files over the network without authentication; this is listed in CISA KEV for required action.
If you're affected
Sensitive system file exposure
Possible credential or config leakage
Risk of follow-on compromise
Service trust and compliance impact
What is it
This vulnerability lets someone who can reach your CentreStack/TrioFox server “trick” it into revealing files that are stored locally on the computer—without needing a username or password. It’s like leaving a file cabinet unlocked through a hidden door on the building’s public hallway: an attacker may be able to grab sensitive system details, which can then be used for further attacks.
Who is affected
This matters if your small business uses Gladinet CentreStack and/or TrioFox for file storage, hosting, or related server-side functions. Because the flaw does not require authentication and is reachable in default configurations, it is mainly a “can an attacker reach it over the network?” question. Reachability gate: treat it as a real risk if the service is reachable from untrusted networks (for example, the internet or other networks attackers may access).
How urgent is it
This is RED because attackers can exploit it remotely without a login to read sensitive files, and it is confirmed as a required action in CISA’s KEV list. Additionally, a public exploit exists, and exploitation/interest has been reported publicly and is described as being exploited in the wild in the findings. Action is required now: upgrade to the fixed version or apply the vendor’s temporary mitigation while you work toward upgrading.
What to do — in detail
Confirm exposure (quick checks)
Identify whether you run Gladinet CentreStack and/or TrioFox on any server.
Determine the installed version for each component and whether it is at or below 16.7.10368.56560 (affected).
Check network exposure:
Is the service reachable from the internet, or from any untrusted network?
If it sits behind a VPN or reverse proxy, verify whether misconfigurations could still allow direct reachability.
Patch (preferred)
Upgrade CentreStack to 16.10.10408.56683.
Ensure the upgrade is completed successfully and that the web/service endpoints restart and operate normally.
For TrioFox, apply the vendor’s corresponding remediation guidance (the findings note vendor instructions and temporary mitigation while patching is developed).
Temporary mitigation if you can’t patch immediately
Use the temporary mitigation Gladinet communicated to customers (check your inbox / vendor communications), as referenced in the findings.
Reduce exposure immediately by restricting network access so it is not reachable from untrusted networks until patched (for example, block external/public access and allow only trusted sources).
Timing / escalation
CISA KEV remediation due date: 2025-11-25.
If you cannot apply mitigations that make the service safe, CISA’s required action says to discontinue use per vendor guidance.
What to monitor
Look for signs of file probing or suspicious requests hitting CentreStack/TrioFox endpoints around the time of exposure.
Review access logs and error logs for unusual patterns (especially requests that resemble attempts to access local file paths).
Technical context
What’s happening
Gladinet CentreStack and TrioFox contain a Local File Inclusion weakness (CWE-552) that—under default installation and configuration—allows an attacker to read arbitrary local files.
How it’s triggered
The key property from the findings is network reachability without authentication and no user interaction required. That means a remote attacker can directly send requests to the exposed service and cause it to disclose local files.
Exploitation status
CISA KEV: YES, with a remediation due date of 2025-11-25.
Findings also indicate exploitation has been observed in the wild and that a public exploit is available.
Impact and exposure
With capability to read sensitive system files, the most likely outcomes are disclosure of configuration, secrets, and system data, which can enable follow-on attacks.
Fixed versions / affected range
The patch availability lists CentreStack fixed in 16.10.10408.56683. The affected range is described in the backstop as all versions prior to and including 16.7.10368.56560.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.
Where each signal puts this CVE on the scale from published to confirmed exploited.
EPSS99th
Public exploit
CISA KEV
PublishedPublic exploitConfirmed exploited
CISA KEV
Listed as exploited in the wild since 2025-11-04.
US federal agencies must remediate by 2025-11-25.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.